CVE-2016-5349 describes a privilege escalation vulnerability affecting Google Android devices utilizing Qualcomm Secure Execution Environment (QSEE). The flaw stems from QSEE failing to adequately verify memory addresses provided by the High Level Operating System (HLOS), allowing secure applications to potentially write to HLOS kernel space instead of legitimate user space. Rated Medium (CVSS 5.5), this vulnerability requires user interaction and local access, but could lead to high confidentiality impact. There is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.1.1CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.