CVE-2016-3874 is a high-severity privilege escalation vulnerability affecting the Qualcomm Wi-Fi driver in Android, specifically on Nexus 5X devices before the 2016-09-05 security update. An attacker can exploit this by crafting an application to send a specific WE_UNIT_TEST_CMD command, bypassing argument validation. This local attack requires user interaction (installing the malicious app) and could lead to complete compromise of confidentiality, integrity, and availability. There is no public exploit code available, it is not listed in CISA's KEV catalog, and it has received minimal community or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.0CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.