PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-8467 Google CVE debrief

CVE-2016-8467 is an Android bootloader vulnerability that can let a local attacker execute arbitrary modem commands on the device. The impact is availability-focused: the issue is described as a local permanent denial of service that may require reflashing the entire operating system, and NVD lists Android versions through 7.1.0 as vulnerable.

Vendor
Google
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-13
Original CVE updated
2026-05-13
Advisory published
2017-01-13
Advisory updated
2026-05-13

Who should care

Android device owners, OEMs, mobile fleet administrators, and security teams responsible for devices running Android 7.1.0 and earlier should pay attention, especially where physical or other local access to devices cannot be tightly controlled.

Technical summary

The CVE describes an elevation-of-privilege issue in the bootloader that allows a local attacker to issue arbitrary modem commands. NVD’s CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, which aligns with the stated availability impact rather than data theft or integrity loss. NVD’s CPE criteria mark Android up to version 7.1.0 as vulnerable, and the recorded weakness category is CWE-264.

Defensive priority

High for affected Android fleets, because the failure mode can be a permanent or near-permanent denial of service and recovery may require reflashing the OS.

Recommended defensive actions

  • Apply the Android security bulletin fixes referenced for 2017-01-01 and verify that the affected bootloader/modem components are updated by the OEM.
  • Inventory Android devices at or below the vulnerable version range listed by NVD and prioritize those still in active service.
  • Restrict local access to managed devices where possible, since the attack requires local privileges.
  • Use OEM-approved recovery and reflash procedures for incident response planning, because the impact may be persistent without a full OS reflash.
  • Validate that device support channels are available for firmware and bootloader remediation before deployment to production fleets.

Evidence notes

Core facts come from the CVE description and NVD metadata: local attacker, arbitrary modem commands, permanent denial of service, Android vulnerability scope, CVSS 5.5/AV:L/PR:L/UI:N/A:H, and CWE-264. The Android security bulletin is the vendor advisory/patch reference in the source corpus. The publishedAt timestamp (2017-01-13) is the CVE record publication time used for disclosure context; the later modifiedAt timestamp is only a record update and not the original issue date.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-8467 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-8467

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-8467 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-8467

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.