CVE-2016-6689
Google Android - Binder Generic ASLR Leak
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30768347.
El enlazador en el kernel en Android en versiones anteriores a 2016-10-05 en dispositivos Nexus permite a atacantes obtener información sensible a través de una aplicación manipulada, vulnerabilidad también conocida como error interno 30768347.
The interaction between the kernel /dev/binder and the usermode Parcel.cpp mean that when a binder object is passed as BINDER_TYPE_BINDER or BINDER_TYPE_WEAK_BINDER, a pointer to that object (in the server process) is leaked to the client process as the cookie value. This leads to a leak of a heap address in many of the privileged binder services, including system_server.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-08-11 CVE Reserved
- 2016-10-10 CVE Published
- 2016-10-12 First Exploit
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/93323 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/139111 | 2016-10-12 | |
https://www.exploit-db.com/exploits/40515 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://source.android.com/security/bulletin/2016-10-01.html | 2017-09-03 |
URL | Date | SRC |
---|