CVE-2016-2421

MEDIUM

Google Android - Access Control

Title source: rule

Description

Setup Wizard in Android 5.1.x before 5.1.1 and 6.x before 2016-04-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26154410.

Scores

CVSS v3 6.1
EPSS 0.0001
EPSS Percentile 2.2%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Classification

CWE
CWE-264
Status draft

Affected Products (4)

google/android
google/android
google/android
google/android

Timeline

Published Apr 18, 2016
Tracked Since Feb 18, 2026