CVE-2017-0706
Description
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-35195787. References: B-RB#120532.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A privilege escalation vulnerability in the Broadcom Wi-Fi driver on Android could allow a local attacker to execute arbitrary code in the kernel.
Vulnerability
An elevation of privilege vulnerability exists in the Broadcom Wi-Fi driver (bcmdhd) used in the Android kernel. The vulnerability is triggered by a local application that sends a crafted request to the driver. Affected versions include Android 7.0 and earlier with kernel versions prior to the July 5, 2017 security patch level [1].
Exploitation
Exploitation requires the attacker to have local access to the device and the ability to install and run a malicious application. The application exploits the vulnerability by providing specially crafted input to the Wi-Fi driver, causing a memory corruption that leads to arbitrary code execution. No additional user interaction is needed once the app is launched [1].
Impact
Successful exploitation grants the attacker arbitrary code execution in the kernel context, resulting in full elevation of privilege. The attacker can then gain root or system-level access, bypassing Android's security sandbox [1].
Mitigation
Google addressed this vulnerability in the Android Security Bulletin for July 2017, with a patch included in the 2017-07-05 security patch level. Users are advised to update their devices to the latest Android security update. No workarounds are available for unpatched devices [1].
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/99482nvdThird Party AdvisoryVDB Entry
- source.android.com/security/bulletin/2017-07-01nvdVendor Advisory
News mentions
0No linked articles in our index yet.