Medium severity6.2NVD Advisory· Published Jul 17, 2017· Updated May 13, 2026
CVE-2016-10398
CVE-2016-10398
Description
Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication tokens (AuthTokens) used by the Trusted Execution Environment (TEE) are protected by a weak challenge. This allows adversaries to replay previously captured responses and use the TEE without authenticating. All apps using authentication-gated cryptography are vulnerable to this attack, which was confirmed on the LG Nexus 5X.
Affected products
2Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- homepages.staff.os3.nl/~delaat/rp/2015-2016/p30/report.pdfnvdTechnical DescriptionThird Party Advisory
News mentions
0No linked articles in our index yet.