CVE-2016-6745
HIGHAndroid < 7.1.0 - Elevation of Privilege in Synaptics Touchscreen Driver
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-6745. PoCs published by codecat007.
AI-analyzed exploit summary The repository contains a functional proof-of-concept exploit for CVE-2016-6745, targeting a race condition in the Android kernel's handling of the `imagesize` and `data` sysfs files. The PoC uses multiple forks to trigger concurrent writes, leading to a heap overflow.
Description
An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-31252388.
Exploits (1)
The repository contains a functional proof-of-concept exploit for CVE-2016-6745, targeting a race condition in the Android kernel's handling of the `imagesize` and `data` sysfs files. The PoC uses multiple forks to trigger concurrent writes, leading to a heap overflow.
References (2)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H