CVE-2016-0812
Last modified
CVE-2016-0812 is a vulnerability of currently unknown severity. The interceptKeyBeforeDispatching function in policy/src/com/android/internal/policy/impl/PhoneWindowManager.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.0 before 2016-02-01 does not properly check for setup completion, which allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 25229538.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
The interceptKeyBeforeDispatching function in policy/src/com/android/internal/policy/impl/PhoneWindowManager.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.0 before 2016-02-01 does not properly check for setup completion, which allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 25229538.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 5.1 | |
| Android | 5.1.0 | |
| Android | 5.1.1 | |
| Android | 6.0 | |
| Android | 6.0.1 |
References
- http://source.android.com/security/bulletin/2016-02-01.htmlVendor Advisory
- http://source.android.com/security/bulletin/2016-02-01.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-0812?
How severe is CVE-2016-0812?
How do I fix CVE-2016-0812?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-0806The Qualcomm Wi-Fi driver in the kernel in Android 4.x befor…
- CVE-2016-0807The get_build_id function in elf_utils.cpp in Debuggerd in A…
- CVE-2016-0808Integer overflow in the getCoverageFormat12 function in Cmap…
- CVE-2016-0809Use-after-free vulnerability in the wifi_cleanup function in…
- CVE-2016-0810media/libmedia/SoundPool.cpp in mediaserver in Android 4.x b…
- CVE-2016-0811Integer overflow in the BnCrypto::onTransact function in med…
- CVE-2016-0813packages/SystemUI/src/com/android/systemui/recents/Alternate…
- CVE-2016-0815The MPEG4Source::fragmentedRead function in MPEG4Extractor.c…
- CVE-2016-0816mediaserver in Android 6.x before 2016-03-01 allows remote a…
- CVE-2016-0818The caching functionality in the TrustManagerImpl class in T…
- CVE-2016-0819The Qualcomm performance component in Android 4.x before 4.4…
- CVE-2016-0820The MediaTek Wi-Fi kernel driver in Android 6.0.1 before 201…
Are you affected by CVE-2016-0812?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
