PT-2016-1583 · Google · Android
Published
2016-03-12
·
Updated
2016-11-28
·
CVE-2016-0825
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android 6.0.1 before 2016-03-01
Description
The issue allows attackers to obtain sensitive TrustZone secure-storage information by leveraging kernel access. This can be achieved by obtaining Signature or SignatureOrSystem access. The vulnerability is related to errors in security settings of the Android operating system. Exploitation of the vulnerability may allow a remote attacker to gain access to protected TrustZone information by utilizing the kernel.
Recommendations
For Android 6.0.1 before 2016-03-01, update the system to a version released after 2016-03-01 to resolve the issue. As a temporary workaround, consider restricting kernel access to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android