PT-2016-7076 · Google · Aosp Launcher
Black2Fan
+1
·
Published
2016-11-25
·
Updated
2016-12-06
·
CVE-2016-6716
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Android versions prior to 2016-11-01
Description
An elevation of privilege issue in the AOSP Launcher could allow a local malicious application to create shortcuts with elevated privileges without user consent. This is a local bypass of user interaction requirements, providing access to functionality that would normally require user initiation or permission.
Recommendations
For Android versions prior to 2016-11-01, update to a version released after 2016-11-01 to resolve the issue. As a temporary workaround, consider restricting the installation of applications from unknown sources to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aosp Launcher