CVE-2015-6607

medium
Published 2015-10-06 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

SQLite before 3.8.9, as used in Android before 5.1.1 LMY48T, allows attackers to gain privileges via a crafted application, aka internal bug 20099586.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@android.com — https://groups.google.com/forum/message/raw?msg=android-security-updates/_Rm-lKnS2M8/dGTcilt0CAAJ

vendor Authored 2026-05-27

Vendor advisory: security@android.com — https://android-review.googlesource.com/#/c/145961/

Application impact

VendorProductVersionsFixed
sqlitesqlite{"endIncluding":"3.8.8.3"}

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.