CVE-2016-0842 is a critical memory corruption vulnerability in the H.264 decoder within libstagefright on Android 6.x devices prior to the April 2016 security update. This flaw allows remote attackers to execute arbitrary code or trigger a denial of service by crafting a malicious media file that exploits mishandled Memory Management Control Operation (MMCO) data. With a CVSS score of 8.4 (High), it presents a significant risk due to its local attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation (KEV listed as No), and public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable. However, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:* | ||
6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.