PT-2016-1583 · Google · Android

Published

2016-03-12

·

Updated

2016-11-28

·

CVE-2016-0825

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android 6.0.1 before 2016-03-01
Description The issue allows attackers to obtain sensitive TrustZone secure-storage information by leveraging kernel access. This can be achieved by obtaining Signature or SignatureOrSystem access. The vulnerability is related to errors in security settings of the Android operating system. Exploitation of the vulnerability may allow a remote attacker to gain access to protected TrustZone information by utilizing the kernel.
Recommendations For Android 6.0.1 before 2016-03-01, update the system to a version released after 2016-03-01 to resolve the issue. As a temporary workaround, consider restricting kernel access to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00884
CVE-2016-0825

Affected Products

Android