CVE-2016-2503 is a privilege escalation vulnerability in the Qualcomm GPU driver affecting Android devices, specifically Nexus 5X and 6P, before the 2016-07-05 security update. An attacker could exploit this flaw by tricking a user into installing a crafted application, leading to high impact on confidentiality, integrity, and availability. With a CVSS score of 7.8 (High), it requires user interaction and local access to the device. While no public exploit code or Metasploit modules are available, the vulnerability garnered significant media attention due to its inclusion in the "QuadRooter" set of flaws, though it is not currently listed as actively exploited in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.