CVE-2016-2475 describes a privilege escalation vulnerability in the Broadcom Wi-Fi driver affecting several Nexus and Pixel C Android devices before the June 2016 security update. An attacker could exploit this flaw through a crafted application to gain elevated privileges for specific system calls. With a CVSS score of 7.8 (High), this vulnerability allows for high impact to confidentiality, integrity, and availability, requiring user interaction (UI:R) to execute. While no public exploit code or Metasploit modules are available, the vulnerability received limited community discussion and media coverage at the time of its disclosure. There is no indication of active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.