VYPR
Unrated severityNVD Advisory· Published Apr 18, 2018· Updated Sep 16, 2024

CVE-2016-10471

CVE-2016-10471

Description

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, an unsigned RTIC health report susceptible to tampering by malware executing in the context of the HLOS may be requested.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unsigned RTIC health report in Qualcomm Snapdragon chipsets allows tampering by malware in HLOS context, leading to integrity compromise.

Vulnerability

The vulnerability resides in the RTIC (Real-Time Integrity Check) health report mechanism on Qualcomm Snapdragon chipsets. The report is unsigned, making it susceptible to tampering by malware executing in the context of the HLOS (High-Level Operating System). Affected chipsets include SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, as well as Snapdragon Automobile platforms. The issue is present in Android builds prior to the 2018-04-05 security patch level [1].

Exploitation

An attacker with malware already running in the HLOS context can request an RTIC health report and modify it because the report lacks cryptographic signing. No additional privileges or user interaction are required beyond the initial malware execution. The attacker can tamper with the report content, potentially masking malicious activity or providing false health status.

Impact

Successful exploitation allows the attacker to tamper with the RTIC health report, which could be used to hide malware presence or mislead integrity checks. This compromises the integrity of the system's health monitoring, potentially allowing further malicious actions without detection.

Mitigation

The fix is included in the Android security patch level 2018-04-05 or later. Users should ensure their devices receive this update. Qualcomm released patches for the affected chipsets, and OEMs incorporated them into their Android security updates [1]. No workaround is available; updating is the only mitigation.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.