Junglewise Threat Intelligence

CVE-2016-8467: Google Android bootloader privilege escalation in Nexus 6 and 6P

CVE-2016-8467 · Severity: medium · CVSS 5.5 · Published 2017-01-13

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the bootloader of Google Nexus 6 and 6P devices allows an attacker with physical access or a compromised PC connection to enable hidden diagnostic modes. This can be used to intercept phone calls, access GPS data, and read or send SMS messages. In some cases, it can also be used to permanently disable the device or require a full re-installation of the operating system to recover.

Technical details

An elevation of privilege vulnerability exists in the bootloader of Nexus 6 and 6P devices due to insufficient restrictions on custom boot modes. A local attacker with ADB access or a physical attacker in fastboot mode can issue 'oem config' commands to enable 'bp-tools', which activates extra USB interfaces including modem diagnostics and AT command interfaces. On Nexus 6, this allows for call interception, GPS tracking, and LTE data sniffing; on Nexus 6P, it can be used to bypass two-factor authentication via SMS eavesdropping or enable ADB without user authorization. The vulnerability is mitigated in Nexus 6 bootloader version 71.22 and Nexus 6P bootloader version 03.64 by forbidding locked bootloaders from booting into these dangerous modes.

Affected products

  • Google Android (Nexus 6, Nexus 6P) Nexus 6 bootloader versions prior to 71.22, Nexus 6P bootloader versions prior to 03.64

Timeline

  • 2016-11-01: patched: Initial patch for Nexus 6 released in November 2016 bulletin.
  • 2017-01-03: advisory: Full disclosure in January 2017 Android Security Bulletin.
  • 2017-01-13: disclosed: NVD publication date.

References

Related threats