CVE-2016-6681 describes an information disclosure vulnerability in the Qualcomm QDSP6v2 audio driver on specific Android devices, including Nexus 5X, Nexus 6P, and Android One, prior to the October 2016 security update. The flaw stems from uninitialized data structures, allowing a crafted application to potentially obtain sensitive information. Rated Medium severity (CVSS 5.5), it requires user interaction (UI:R) with a malicious application to exploit, but has a high confidentiality impact (C:H). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.0CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.