VYPR
Unrated severityNVD Advisory· Published Apr 18, 2018· Updated Sep 17, 2024

CVE-2016-10424

CVE-2016-10424

Description

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 820, SD 820A, SD 835, SD 845, and SD 850, upgrading LibPNG from 1.6.12 to 1.6.21 fixes multiple issues with different CWEs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Upgrading LibPNG in Qualcomm Android chipsets from 1.6.12 to 1.6.21 fixes multiple memory corruption issues with different CWEs.

Vulnerability

Multiple memory corruption vulnerabilities exist in LibPNG versions 1.6.12 through 1.6.20 as used in Android on Qualcomm Snapdragon Automobile, Mobile, and Wear chipsets. The issues are resolved by upgrading LibPNG to version 1.6.21. Affected SoCs include MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 820, SD 820A, SD 835, SD 845, and SD 850. Android security patch level 2018-04-05 or earlier is vulnerable [1].

Exploitation

An attacker could exploit these vulnerabilities by providing a specially crafted PNG image to an application or service that processes images using the vulnerable LibPNG library. No specific user interaction beyond opening the image is required. The exact attack vector depends on the specific CWE, but generally the attacker needs to convince a user or system to decode a malicious PNG file [1].

Impact

Successful exploitation could lead to information disclosure, denial of service, or arbitrary code execution in the context of the affected process. The severity is rated as High with a CVSS v3 base score of 9.8 (Critical). The attacker could gain access to sensitive data, cause a system crash, or modify memory [1].

Mitigation

The vulnerabilities are fixed in Android security patch level 2018-04-05 or later. Users should apply the security update as soon as it becomes available from their device manufacturer. No workarounds are documented for these specific LibPNG issues. Devices should be updated to a newer Android security patch level to mitigate these vulnerabilities [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.