CVE-2016-2496
published 2016-06-13CVE-2016-2496: The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjacking attacks and access arbitrary…
PriorityP341critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.91%
56.0th percentile
The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjacking attacks and access arbitrary private-storage files by creating a partially overlapping window, aka internal bug 26677796.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-98hv-c54f-3q9x: The Framework UI permission-dialog implementation in Android 6
ghsa_unreviewed·2022-05-17
CVE-2016-2496 [CRITICAL] CWE-1021 GHSA-98hv-c54f-3q9x: The Framework UI permission-dialog implementation in Android 6
The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjacking attacks and access arbitrary private-storage files by creating a partially overlapping window, aka internal bug 26677796.
OSV
CVE-2016-2496: The Framework UI permission-dialog implementation in Android 6
osv·2016-06-13·CVSS 9.8
CVE-2016-2496 [CRITICAL] CVE-2016-2496: The Framework UI permission-dialog implementation in Android 6
The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjacking attacks and access arbitrary private-storage files by creating a partially overlapping window, aka internal bug 26677796.
Android
CVE-2016-2496: Android Security Bulletin 2016-06-01
CVE: CVE-2016-2496
Severity: MEDIUM
Affected AOSP versions: 6
vendor_android·2016-06-01·CVSS 9.8
CVE-2016-2496 [CRITICAL] CVE-2016-2496: Android Security Bulletin 2016-06-01
CVE: CVE-2016-2496
Severity: MEDIUM
Affected AOSP versions: 6
Android Security Bulletin 2016-06-01
CVE: CVE-2016-2496
Severity: MEDIUM
Affected AOSP versions: 6.0, 6.1
No detection rules found.
No public exploits indexed.
arXiv
Hey Google, What Exactly Do Your Security Patches Tell Us? A Large-Scale Empirical Study on Android Patched Vulnerabilities
arxiv_fulltext·2019-05-22
Hey Google, What Exactly Do Your Security Patches Tell Us? A Large-Scale Empirical Study on Android Patched Vulnerabilities
1.55cm
[1]
\@fnsymbol#1
Hey Google, What Exactly Do Your Security Patches Tell Us?\ Large-Scale Empirical Study on Android Patched Vulnerabilities
Sadegh Farhang Sadegh Farhang and Mehmet Bahadir Kirdan equally contributed to this work.
Pennsylvania State University
[email protected]
Mehmet Bahadir Kirdan 1
Technical University of Munich
[email protected]
Aron Laszka
University of Houston
[email protected]
Jens Grossklags
Technical University of Munich
[email protected]
## Abstract
Android has the largest market share among smartphone platforms worldwide with more than one billion active devices.
Like other platforms, security patches play a pivotal role in keeping Android devices safe from the exploitation of known vulnerabilities. Previous research efforts have documente
arXiv
An Empirical Study on Android-related Vulnerabilities
arxiv_fulltext·2017-04-11
An Empirical Study on Android-related Vulnerabilities
An Empirical Study on\ -related Vulnerabilities
Mario Linares-V\'asquez^1, Gabriele Bavota^2, Camilo Escobar-Vel\'asquez^1
^1 Systems and Computing Engineering Department, Universidad de los Andes, Bogot\'a, Colombia
^2 Faculty of Informatics, Universita della Svizzera Italiana, Lugano, Switzerland
[email protected], [email protected], [email protected]
## Abstract
Mobile devices are used more and more in everyday life. They are our cameras, wallets, and keys. Basically, they embed most of our private information in our pocket. For this and other reasons, mobile devices, and in particular the software that runs on them, are considered first-class citizens in the software-vulnerabilities landscape. Several studies investigated the software-vulnerabilities ph
http://source.android.com/security/bulletin/2016-06-01.htmlhttps://android.googlesource.com/platform/frameworks/base/+/613f63b938145bb86cd64fe0752eaf5e99b5f628https://android.googlesource.com/platform/frameworks/native/+/03a53d1c7765eeb3af0bc34c3dff02ada1953fbfhttps://android.googlesource.com/platform/packages/apps/PackageInstaller/+/2068c7997265011ddc5e4dfa3418407881f7f81ehttp://source.android.com/security/bulletin/2016-06-01.htmlhttps://android.googlesource.com/platform/frameworks/base/+/613f63b938145bb86cd64fe0752eaf5e99b5f628https://android.googlesource.com/platform/frameworks/native/+/03a53d1c7765eeb3af0bc34c3dff02ada1953fbfhttps://android.googlesource.com/platform/packages/apps/PackageInstaller/+/2068c7997265011ddc5e4dfa3418407881f7f81e
2016-06-13
Published