Executive brief
A security vulnerability in the Android Audioserver component could allow a malicious application installed on a device to access sensitive information it should not have permission to see. This could lead to the unauthorized disclosure of user data or system information. Users are protected by installing the January 2017 security update or later.
Technical details
An information disclosure vulnerability exists in the Android Audioserver component (specifically tracked via Android IDs A-32438594 and A-32635664). The flaw allows a local malicious application to bypass standard permission levels to access sensitive data outside of its sandbox. The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Exploitation requires a user to install and run a malicious application on the device. Google addressed this issue in the January 2017 Android Security Bulletin with the 2017-01-01 security patch level.
Affected products
- Google Android 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1
Timeline
- 2016-12-05: other: Partners notified of the vulnerability
- 2017-01-03: advisory: Android Security Bulletin published
- 2017-01-13: disclosed: NVD publication date