PatchSiren cyber security CVE debrief
CVE-2016-8467 Google CVE debrief
CVE-2016-8467 is an Android bootloader vulnerability that can let a local attacker execute arbitrary modem commands on the device. The impact is availability-focused: the issue is described as a local permanent denial of service that may require reflashing the entire operating system, and NVD lists Android versions through 7.1.0 as vulnerable.
- Vendor
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-13
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-13
- Advisory updated
- 2026-05-13
Who should care
Android device owners, OEMs, mobile fleet administrators, and security teams responsible for devices running Android 7.1.0 and earlier should pay attention, especially where physical or other local access to devices cannot be tightly controlled.
Technical summary
The CVE describes an elevation-of-privilege issue in the bootloader that allows a local attacker to issue arbitrary modem commands. NVD’s CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, which aligns with the stated availability impact rather than data theft or integrity loss. NVD’s CPE criteria mark Android up to version 7.1.0 as vulnerable, and the recorded weakness category is CWE-264.
Defensive priority
High for affected Android fleets, because the failure mode can be a permanent or near-permanent denial of service and recovery may require reflashing the OS.
Recommended defensive actions
- Apply the Android security bulletin fixes referenced for 2017-01-01 and verify that the affected bootloader/modem components are updated by the OEM.
- Inventory Android devices at or below the vulnerable version range listed by NVD and prioritize those still in active service.
- Restrict local access to managed devices where possible, since the attack requires local privileges.
- Use OEM-approved recovery and reflash procedures for incident response planning, because the impact may be persistent without a full OS reflash.
- Validate that device support channels are available for firmware and bootloader remediation before deployment to production fleets.
Evidence notes
Core facts come from the CVE description and NVD metadata: local attacker, arbitrary modem commands, permanent denial of service, Android vulnerability scope, CVSS 5.5/AV:L/PR:L/UI:N/A:H, and CWE-264. The Android security bulletin is the vendor advisory/patch reference in the source corpus. The publishedAt timestamp (2017-01-13) is the CVE record publication time used for disclosure context; the later modifiedAt timestamp is only a record update and not the original issue date.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-8467 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-8467
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-8467 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-8467
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://securityintelligence.com/android-vulnerabilities-attacking-nexus-6-and-6p-custom-boot-modes/
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://source.android.com/security/bulletin/2017-01-01.html
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.