CVE-2017-14876 is a critical out-of-bounds write vulnerability affecting Android for MSM, Firefox OS for MSM, and QRD Android versions prior to 2017-06-21. This flaw, stemming from a lack of bounds checking on user-supplied input, allows an unauthenticated attacker to execute arbitrary code with kernel privileges remotely. Rated 9.8 CRITICAL on CVSS, it poses a severe risk of complete compromise (confidentiality, integrity, availability). Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.