CVE-2015-8939 is a high-severity privilege escalation vulnerability affecting Google Android devices, specifically the Nexus 7 (2013) before the 2016-08-05 update. It stems from insufficient validation of color stage data in the mdp4_util.c driver, allowing attackers to gain elevated privileges through a crafted application. The attack requires user interaction (UI:R) but has low attack complexity (AC:L), with potential for high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.