CVE-2016-2477 is a high-severity vulnerability affecting the mediaserver component in various Android versions (4.x, 5.0.x, 5.1.x, and 6.x before 2016-06-01). It stems from improper pointer handling in the mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp file. An attacker could exploit this by tricking a user into installing a crafted application, leading to privilege escalation, including Signature or SignatureOrSystem access. The CVSSv3 score is 7.8 (High), indicating a local attack vector with low complexity and high impact on confidentiality, integrity, and availability. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting limited public awareness or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:* | ||
4.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:* | ||
4.0.2CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:* | ||
4.0.3CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.3:*:*:*:*:*:*:* | ||
4.0.4CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.