CVE-2016-3875
MEDIUMAndroid 6.x <2016-09-01 - Privilege Escalation
Title source: llmDescription
server/wm/WindowManagerService.java in Android 6.x before 2016-09-01 does not enforce the DISALLOW_SAFE_BOOT setting, which allows physically proximate attackers to bypass intended access restrictions and boot to safe mode via unspecified vectors, aka internal bug 26251884.
References (4)
Scores
CVSS v3
6.8
EPSS
0.0003
EPSS Percentile
6.6%
Attack Vector
PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-264
Status
published
Affected Products (3)
google/android
google/android
n/a/n/a
Timeline
Published
Sep 11, 2016
Tracked Since
Feb 18, 2026