CVE-2016-3820 is a critical vulnerability affecting the mediaserver component in Android 6.x devices prior to the August 2016 security update. It stems from improper handling of slice numbers by the ih264d decoder, allowing remote attackers to execute arbitrary code or cause a denial of service via memory corruption through a crafted media file. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network without user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no public exploit code available in common repositories like Metasploit or ExploitDB, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:* | ||
6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.