internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism, and send premium SMS messages during the Setup Wizard provisioning stage, via unspecified vectors, aka internal bug 29420123.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published: 2016-09-11T21:00:00

Updated: 2024-08-06T00:10:31.805Z

Reserved: 2016-03-30T00:00:00

Link: CVE-2016-3888

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-09-11T21:59:32.840

Modified: 2017-08-13T01:29:08.927

Link: CVE-2016-3888

cve-icon Redhat

No data.