CVE-2016-3917 describes a critical vulnerability in the fingerprint login feature of Android versions 6.0.1 and 7.0 prior to their October 2016 security updates. This flaw allows a physically proximate attacker to bypass authentication and gain access as any user on a locked device. The vulnerability carries a high CVSS score of 7.8, indicating a significant risk. It requires local access to the device but is low complexity to exploit, potentially leading to full compromise of confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, nor is public exploit code available in common repositories like Metasploit or ExploitDB. The vulnerability has also received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.