VYPR
Critical severity9.8NVD Advisory· Published Oct 4, 2017· Updated May 13, 2026

CVE-2017-0824

CVE-2017-0824

Description

An elevation of privilege vulnerability in the Broadcom wifi driver. Product: Android. Versions: Android kernel. Android ID: A-37622847. References: B-V2017063001.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A critical elevation-of-privilege vulnerability in the Broadcom Wi-Fi driver on Android kernels could lead to remote code execution.

Vulnerability

A critical elevation-of-privilege vulnerability exists in the Broadcom Wi-Fi driver used by the Android kernel. The issue is identified by Android ID A-37622847 and is addressed in the October 2017 Pixel/Nexus Security Bulletin [1]. This vulnerability affects Android kernel versions and can be exploited remotely without user interaction [1].

Exploitation

An attacker can exploit this vulnerability remotely over the air, requiring no additional execution privileges and no user interaction [1]. The exact steps involve sending a specially crafted Wi-Fi frame to a vulnerable device, which triggers the flaw in the Broadcom driver.

Impact

Successful exploitation leads to elevation of privilege, potentially allowing the attacker to execute arbitrary code within the context of the kernel [1]. This can result in full compromise of the affected Android device's security, including access to all user data and system functions.

Mitigation

Google released a fix as part of the 2017-10-01 Pixel/Nexus Security Bulletin [1]. Users should apply the Android security update dated October 5, 2017, or later, which includes the patch for this vulnerability. No workarounds are mentioned in the available references, and it is not listed on the CISA KEV [1].

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • Google/Android2 versions
    cpe:2.3:o:google:android:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:google:android:*:*:*:*:*:*:*:*range: <=8.0
    • (no CPE)range: Android kernel

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.