Bypass of Factory Reset Protection in Android Setup Wizard

Bypass of Factory Reset Protection in Android Setup Wizard

CVE-2016-3888 · LOW Severity

AV:L/AC:L/AU:N/C:N/I:P/A:N

internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism, and send premium SMS messages during the Setup Wizard provisioning stage, via unspecified vectors, aka internal bug 29420123.

Learn more about our Cis Benchmark Audit For Google Android.