Information Disclosure Vulnerability in Android SurfaceFlinger Service

Information Disclosure Vulnerability in Android SurfaceFlinger Service

CVE-2016-3836 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:N/A:N

The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive information via a crafted application, related to lack of a default constructor in include/ui/FrameStats.h, aka internal bug 28592402.

Learn more about our Cis Benchmark Audit For Google Android.