CVE-2016-2435 describes a privilege escalation vulnerability in the NVIDIA video driver on Google Nexus 9 devices running Android versions prior to May 1, 2016. A malicious application could exploit this flaw to gain elevated privileges on the affected device. With a CVSS score of 7.8 (High), this vulnerability allows an attacker to achieve high confidentiality, integrity, and availability impacts through a low-complexity attack requiring user interaction. While there is no known public exploit code or Metasploit module, the vulnerability has received some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.