CVE-2016-0828 describes an information disclosure vulnerability in the mediaserver component of Android 5.x and 6.x, specifically within the BnGraphicBufferConsumer::onTransact function. This flaw allows an attacker to obtain sensitive information, such as Signature or SignatureOrSystem access, by triggering an ATTACH_BUFFER action due to an uninitialized slot variable. Rated with a CVSSv3 score of 7.5 (High), this vulnerability is network-exploitable with low attack complexity, requiring no privileges or user interaction, and primarily impacts confidentiality. The FAUCET Risk Score is 48/100. There is no evidence of active exploitation (KEV: No, Hot List: Inactive), and no public exploit code is available via Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has received moderate community attention with 2 mentions and 2 media articles, indicating some awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:o:google:android:5.0:*:*:*:*:*:*:* | ||
5.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:5.0.1:*:*:*:*:*:*:* | ||
5.0.2CPE matchmatch criteria | cpe:2.3:o:google:android:5.0.2:*:*:*:*:*:*:* | ||
5.1CPE matchmatch criteria | cpe:2.3:o:google:android:5.1:*:*:*:*:*:*:* | ||
5.1.0CPE matchmatch criteria | cpe:2.3:o:google:android:5.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.