VYPR
High severity7.8NVD Advisory· Published Jun 13, 2017· Updated May 13, 2026

CVE-2016-10338

CVE-2016-10338

Description

A privilege escalation vulnerability in Android's RPMB processing allows an attacker to write critical secure storage data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A privilege escalation vulnerability in Android's RPMB processing allows an attacker to write critical secure storage data.

Vulnerability

The issue is in RPMB (Replay Protected Memory Block) processing in all Android releases from CAF (Code Aurora Forum) using the Linux kernel. The vulnerability is present in the kernel's handling of RPMB requests, which are used for secure storage operations. Affected versions include all Android releases from CAF using the Linux kernel as of June 2017 [1].

Exploitation

An attacker needs to have local access and the ability to execute arbitrary code in the context of the kernel. The exploitation involves sending crafted RPMB commands that trigger the vulnerability. The exact sequence of steps is not detailed in the available references, but it is likely achieved through a malicious application that exploits a missing bounds check or similar flaw [1].

Impact

Successful exploitation leads to elevation of privilege, allowing an attacker to gain kernel-level access. This enables full control over the device's secure storage, meaning the attacker can read, modify, or delete RPMB data. This compromises the confidentiality, integrity, and availability of secure data, such as DRM keys or device credentials [1].

Mitigation

The fix was included in the Android Security Bulletin dated June 1, 2017. Users should apply the security update to their devices. No workaround is provided, as the fix requires a kernel update [1].

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
  • Qualcomm, Inc./All Qualcomm productsv5
    Range: All Android releases from CAF using the Linux kernel

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.