CVE-2016-5348 describes a denial-of-service vulnerability in the GPS component of various Android versions (4.x, 5.0.x, 5.1.x, 6.x, and 7.0). An unauthenticated attacker can exploit this by acting as a man-in-the-middle, spoofing Qualcomm GPS servers (gpsonextra.net or izatcloud.net), and sending a large xtra.bin or xtra2.bin file. This leads to excessive memory consumption, causing the affected Android device to hang or reboot. The vulnerability has a CVSSv3 score of 5.9 (Medium), indicating a network-based attack with high impact on availability, but requiring high attack complexity. While not currently on CISA's KEV catalog or actively exploited, public exploit code is available on ExploitDB (EDB-40502). Despite this, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:* | ||
4.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:* | ||
4.0.2CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:* | ||
4.0.3CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.3:*:*:*:*:*:*:* | ||
4.0.4CPE matchmatch criteria | cpe:2.3:o:google:android:4.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.