CVE-2016-3851 describes a privilege escalation vulnerability in the LG Electronics bootloader on Nexus 5X devices running Android versions prior to 2016-08-05. This high-severity vulnerability (CVSS 8.1) allows unauthenticated attackers to gain elevated privileges by exploiting a flaw in a privileged process, requiring high attack complexity but leading to complete compromise of confidentiality, integrity, and availability. Despite its severity, there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in CISA's KEV catalog, indicating no active exploitation. Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.