server/wm/WindowManagerService.java in Android 6.x before 2016-09-01 does not enforce the DISALLOW_SAFE_BOOT setting, which allows physically proximate attackers to bypass intended access restrictions and boot to safe mode via unspecified vectors, aka internal bug 26251884.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2016-09-11 14:59
Updated : 2017-08-12 18:29
NVD link : CVE-2016-3875
Mitre link : CVE-2016-3875
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
- android