CVE-2016-3923

Published on: 10/10/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:01 PM UTC

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Certain versions of Android from Google contain the following vulnerability:

The Accessibility services in Android 7.0 before 2016-10-01 mishandle motion events, which allows attackers to conduct touchjacking attacks and consequently gain privileges via a crafted application, aka internal bug 30647115.

  • CVE-2016-3923 has been assigned by [email protected] to track the vulnerability - currently rated as MEDIUM severity.

CVSS3 Score: 5.5 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
LOCAL LOW NONE REQUIRED
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE HIGH NONE

CVSS2 Score: 4.3 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK MEDIUM NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE PARTIAL NONE

CVE References

Description Tags Link
5f256310187b4ff2f13a7abb9afed9126facd7bc - platform/frameworks/base - Git at Google Issue Tracking
Patch
android.googlesource.com
text/html
URL Logo CONFIRM android.googlesource.com/platform/frameworks/base/+/5f256310187b4ff2f13a7abb9afed9126facd7bc
Android Security Bulletin—October 2016 | Android Open Source Project Vendor Advisory
source.android.com
text/html
URL Logo CONFIRM source.android.com/security/bulletin/2016-10-01.html
Google Android CVE-2016-3923 Privilege Escalation Vulnerability cve.report (archive)
text/html
URL Logo BID 93310

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Operating
System
GoogleAndroidAllAllAllAll
  • cpe:2.3:o:google:android:*:*:*:*:*:*:*:*: