CVE-2016-10471
Description
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, an unsigned RTIC health report susceptible to tampering by malware executing in the context of the HLOS may be requested.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An unsigned RTIC health report in Qualcomm Snapdragon chipsets allows tampering by malware in HLOS context, leading to integrity compromise.
Vulnerability
The vulnerability resides in the RTIC (Real-Time Integrity Check) health report mechanism on Qualcomm Snapdragon chipsets. The report is unsigned, making it susceptible to tampering by malware executing in the context of the HLOS (High-Level Operating System). Affected chipsets include SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, as well as Snapdragon Automobile platforms. The issue is present in Android builds prior to the 2018-04-05 security patch level [1].
Exploitation
An attacker with malware already running in the HLOS context can request an RTIC health report and modify it because the report lacks cryptographic signing. No additional privileges or user interaction are required beyond the initial malware execution. The attacker can tamper with the report content, potentially masking malicious activity or providing false health status.
Impact
Successful exploitation allows the attacker to tamper with the RTIC health report, which could be used to hide malware presence or mislead integrity checks. This compromises the integrity of the system's health monitoring, potentially allowing further malicious actions without detection.
Mitigation
The fix is included in the Android security patch level 2018-04-05 or later. Users should ensure their devices receive this update. Qualcomm released patches for the affected chipsets, and OEMs incorporated them into their Android security updates [1]. No workaround is available; updating is the only mitigation.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Qualcomm, Inc./Snapdragon Automobile, Snapdragon Mobilev5Range: SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/103671mitrevdb-entryx_refsource_BID
- source.android.com/security/bulletin/2018-04-01mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.