CVE-2016-2419 is a critical vulnerability affecting Android 6.x devices prior to the April 2016 security update, specifically within the mediaserver component's IDrm.cpp. This flaw allows attackers to obtain sensitive information from process memory due to an uninitialized key-request data structure, potentially bypassing protection mechanisms like Signature or SignatureOrSystem access. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk with network-based, low-complexity attacks leading to high confidentiality, integrity, and availability impacts. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with over 10 mentions, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:* | ||
6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.