CVE-2016-6725

CRITICAL

Google Android < 7.0 - Improper Access Control

Title source: rule

Description

A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Android ID: A-30515053. References: Qualcomm QC-CR#1050970.

Exploits (1)

github STUB 8 stars
by codecat007 · cpoc
https://github.com/codecat007/cvehub/tree/main/android/kernel/CVE-2016-6725

Scores

CVSS v3 9.8
EPSS 0.0306
EPSS Percentile 86.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (3)
google/android < 7.0
Google Inc./Android Kernel-3.10
Google Inc./Android Kernel-3.18
Published Nov 25, 2016
Tracked Since Feb 18, 2026