8.8
CVSSv3

CVE-2016-6754

Published: 25/11/2016 Updated: 24/12/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A remote code execution vulnerability in Webview in Android 5.0.x prior to 5.0.2, 5.1.x prior to 5.1.1, and 6.x prior to 2016-11-05 could enable a remote malicious user to execute arbitrary code when the user is navigating to a website. This issue is rated as High due to the possibility of remote code execution in an unprivileged process. Android ID: A-31217937.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 5.1.0

google android

google android 5.0

google android 5.0.1

google android 5.1

google android 6.0

Exploits

<!-- author:@oldfresher --> <html> <div id="message" style="color: red;"></div> <script> function gc(){ for(var i=0;i<0x200000;i++){ new Array; } } function to_hex(num){ return (num>>>0)toString(16); } function log (){ var str = "<h3>"; for(var i=0;i<argumentslength;i+ ...

Github Repositories

Full exploit of CVE-2016-6754(BadKernel) and slide of SyScan360 2016

BadKernel #full exploit for CVE-2016-6754(BadKernel) #slide for syscan2016 shanghai "BadKernel --- exploit V8 with a typo"