CVE-2016-2421
MEDIUMGoogle Android - Access Control
Title source: ruleDescription
Setup Wizard in Android 5.1.x before 5.1.1 and 6.x before 2016-04-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26154410.
Scores
CVSS v3
6.1
EPSS
0.0001
EPSS Percentile
2.2%
Attack Vector
PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Classification
CWE
CWE-264
Status
draft
Affected Products (4)
google/android
google/android
google/android
google/android
Timeline
Published
Apr 18, 2016
Tracked Since
Feb 18, 2026