Information Disclosure Vulnerability in Qualcomm Components for Android Devices
CVE-2016-3906

5.5MEDIUM

Key Information:

Vendor
Google
Vendor
CVE Published:
25 November 2016

Summary

An information disclosure vulnerability exists within various Qualcomm components such as the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android versions released prior to November 5, 2016. This vulnerability allows a local malicious application to gain access to sensitive data beyond its designated permission levels, potentially compromising user privacy and security. Exploitation of this flaw necessitates the initial compromise of a privileged process, making it a noteworthy concern for Android users and app developers.

Affected Version(s)

Android Kernel-3.10 Android Kernel-3.10

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.