CVE-2016-7989 is a denial-of-service vulnerability affecting Samsung Galaxy S4 through S7 devices. A remotely sent, malformed OTA WAP PUSH SMS containing an OMACP message triggers an unhandled ArrayIndexOutOfBoundsException, causing the Android runtime to crash repeatedly. This renders the device unusable until a factory reset is performed. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a high-severity issue that can be exploited remotely without user interaction, leading to a complete loss of availability for the affected device. Its EPSS score is low, suggesting a low likelihood of exploitation in the wild. There is no known active exploitation, and no public exploit code is available in Metasploit or ExploitDB. While there is limited community discussion and media coverage, one article highlights its potential for ransomware attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.2CPE matchmatch criteria | cpe:2.3:o:google:android:4.2.2:*:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:o:google:android:4.3:*:*:*:*:*:*:* | ||
4.3.1CPE matchmatch criteria | cpe:2.3:o:google:android:4.3.1:*:*:*:*:*:*:* | ||
4.4CPE matchmatch criteria | cpe:2.3:o:google:android:4.4:*:*:*:*:*:*:* | ||
4.4.1CPE matchmatch criteria | cpe:2.3:o:google:android:4.4.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.