Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-2452

24
FAUCET Score

CVE-2016-2452 describes a buffer size validation vulnerability in the libstagefright component of Android's mediaserver, specifically affecting versions 4.x through 6.x prior to specific patch levels. An attacker could exploit this flaw via a crafted application to gain elevated privileges, such as Signature or SignatureOrSystem access. With a CVSS score of 7.8 (High), this vulnerability has a low attack complexity and requires user interaction (installing a malicious app). Successful exploitation could lead to high confidentiality, integrity, and availability impacts. Currently, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not listed in the CISA KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
4.0CPE matchmatch criteria
cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:*
4.0.2CPE matchmatch criteria
cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:*
4.0.3CPE matchmatch criteria
cpe:2.3:o:google:android:4.0.3:*:*:*:*:*:*:*
4.0.4CPE matchmatch criteria
cpe:2.3:o:google:android:4.0.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.8HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.49%
Probability of exploitation in next 30 days
EPSS Percentile
39.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0049 is in the 39th percentile among its peer group of 11,616 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

googlevendor investigatingvia nvd_reference
View patch

References

android.googlesource.com / platform/frameworks/av/+/44749eb4f273f0eb681d0fa013e3beef754fa687
android.googlesource.com / platform/frameworks/av/+/65756b4082cd79a2d99b2ccb5b392291fd53703f
android.googlesource.com / platform/frameworks/av/+/daa85dac2055b22dabbb3b4e537597e6ab73a866
source.android.com / security/bulletin/2016-05-01.html
Vendor Advisory