CVE-2016-10424
Description
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 820, SD 820A, SD 835, SD 845, and SD 850, upgrading LibPNG from 1.6.12 to 1.6.21 fixes multiple issues with different CWEs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Upgrading LibPNG in Qualcomm Android chipsets from 1.6.12 to 1.6.21 fixes multiple memory corruption issues with different CWEs.
Vulnerability
Multiple memory corruption vulnerabilities exist in LibPNG versions 1.6.12 through 1.6.20 as used in Android on Qualcomm Snapdragon Automobile, Mobile, and Wear chipsets. The issues are resolved by upgrading LibPNG to version 1.6.21. Affected SoCs include MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 820, SD 820A, SD 835, SD 845, and SD 850. Android security patch level 2018-04-05 or earlier is vulnerable [1].
Exploitation
An attacker could exploit these vulnerabilities by providing a specially crafted PNG image to an application or service that processes images using the vulnerable LibPNG library. No specific user interaction beyond opening the image is required. The exact attack vector depends on the specific CWE, but generally the attacker needs to convince a user or system to decode a malicious PNG file [1].
Impact
Successful exploitation could lead to information disclosure, denial of service, or arbitrary code execution in the context of the affected process. The severity is rated as High with a CVSS v3 base score of 9.8 (Critical). The attacker could gain access to sensitive data, cause a system crash, or modify memory [1].
Mitigation
The vulnerabilities are fixed in Android security patch level 2018-04-05 or later. Users should apply the security update as soon as it becomes available from their device manufacturer. No workarounds are documented for these specific LibPNG issues. Devices should be updated to a newer Android security patch level to mitigate these vulnerabilities [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Qualcomm, Inc./Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wearv5Range: MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 820, SD 820A, SD 835, SD 845, SD 850
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/103671mitrevdb-entryx_refsource_BID
- source.android.com/security/bulletin/2018-04-01mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.