media/libmedia/IOMX.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize certain metadata buffer pointers, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26324358.
Metrics
Affected Vendors & Products
References
History
Sun, 13 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: google_android
Published: 2016-04-18T00:00:00
Updated: 2024-08-05T23:24:49.292Z
Reserved: 2016-02-18T00:00:00
Link: CVE-2016-2418

No data.

Status : Deferred
Published: 2016-04-18T00:59:24.883
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-2418

No data.