CVE-2015-6642
critical
CVSS v3
9.8
CVSS v2
7.8
VIR risk
9.8
Description
The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24157888.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@android.com — http://source.android.com/security/bulletin/2016-01-01.html
References
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.