VYPR
Unrated severityNVD Advisory· Published Apr 7, 2020· Updated Aug 6, 2024

CVE-2016-11044

CVE-2016-11044

Description

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an application's signature can be bypassed during installation. The Samsung ID is SVE-2016-5923 (June 2016).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Samsung mobile devices with L(5.0/5.1) and M(6.0) software allow bypassing application signature verification during installation.

Vulnerability

During the installation of applications on Samsung mobile devices running Android Lollipop (5.0/5.1) or Marshmallow (6.0) with fingerprint support, the verification of the application's cryptographic signature can be bypassed. This allows an application to be installed without proper signature validation. The affected software versions are L(5.0/5.1) and M(6.0).

Exploitation

An attacker with the ability to install applications on the device (e.g., through physical access or via a malicious app) can craft an application with an invalid or spoofed signature that bypasses the signature check. The exact attack vector and prerequisites are not disclosed in the available references.

Impact

Successful exploitation allows the installation of an application that would normally be rejected due to invalid or mismatched signatures. This may lead to execution of untrusted code within the application sandbox, potentially compromising user data or device functionality depending on the installed application's permissions.

Mitigation

Samsung addressed this vulnerability in a security update released in June 2016 as part of the Samsung Mobile Security program (SVE-2016-5923). Users should update their devices to the latest firmware. No workaround is documented for unpatched devices.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.