PT-2016-1583 · Google · Android
Publicado
2016-03-12
·
Atualizado
2016-11-28
·
CVE-2016-0825
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android 6.0.1 before 2016-03-01
Description
The issue allows attackers to obtain sensitive TrustZone secure-storage information by leveraging kernel access. This can be achieved by obtaining Signature or SignatureOrSystem access. The vulnerability is related to errors in security settings of the Android operating system. Exploitation of the vulnerability may allow a remote attacker to gain access to protected TrustZone information by utilizing the kernel.
Recommendations
For Android 6.0.1 before 2016-03-01, update the system to a version released after 2016-03-01 to resolve the issue. As a temporary workaround, consider restricting kernel access to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Android