CVE-2016-2442 describes a privilege escalation vulnerability within the Qualcomm buspm driver on specific Google Nexus devices (5X, 6, and 6P) running Android versions prior to May 2016. An attacker could exploit this flaw by tricking a user into installing a specially crafted application. The vulnerability carries a CVSSv3 score of 7.0 (HIGH), indicating a high potential for impact on confidentiality, integrity, and availability, though it requires user interaction and has high attack complexity. There is no evidence of active exploitation, nor are there publicly available exploit modules like Metasploit or Nuclei, and it is not listed in the CISA KEV catalog. Community discussion and media coverage for this CVE are minimal, with only one article from SecurityWeek mentioning its patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.