CVE-2016-2473 describes a critical privilege escalation vulnerability in the Qualcomm Wi-Fi driver affecting Android devices, specifically the Nexus 7 (2013) before the 2016-06-01 security update. This flaw allows an unauthenticated attacker to gain full control over the device through a crafted application, as indicated by its CVSS score of 9.8 (CRITICAL). While no public exploit code or Metasploit modules are available, and it is not listed in CISA's KEV catalog, the vulnerability has received some community discussion and media coverage. Despite its age, the high severity and potential for complete system compromise warrant attention for affected legacy devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.