The fingerprint login feature in Android 6.0.1 before 2016-10-01 and 7.0 before 2016-10-01 does not track the user account during the authentication process, which allows physically proximate attackers to authenticate as an arbitrary user by leveraging lockscreen access, aka internal bug 30744668.
References
| Link | Resource |
|---|---|
| https://android.googlesource.com/platform/frameworks/base/+/f5334952131afa835dd3f08601fb3bced7b781cd | Issue Tracking Patch |
| http://source.android.com/security/bulletin/2016-10-01.html | Vendor Advisory |
| http://www.securityfocus.com/bid/93298 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2016-10-10 03:59
Updated : 2016-11-28 12:13
NVD link : CVE-2016-3917
Mitre link : CVE-2016-3917
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
- android


