PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-0398 Google CVE debrief

CVE-2017-0398 is a moderate-severity Android information disclosure issue in Audioserver. A local malicious app could access data beyond its permission level, exposing sensitive information on affected devices.

Vendor
Google
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-13
Original CVE updated
2026-05-13
Advisory published
2017-01-13
Advisory updated
2026-05-13

Who should care

Android OEMs, enterprise mobility teams, and device owners running affected Android releases should care most, especially where third-party apps are installed or managed at scale.

Technical summary

The CVE record describes a local, user-interaction-dependent disclosure flaw in Audioserver with CVSS 3.0 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N and CWE-200. The issue can leak sensitive data outside normal permission boundaries. The supplied record lists affected Android releases across 4.4.4 through 7.1, and the NVD CPE entries enumerate 4.4.4, 5.1.1, 6.0, 6.0.1, 7.0, and 7.1.0.

Defensive priority

Medium. The flaw can expose sensitive data, but it requires local access and user interaction, so patching should be prioritized for managed fleets and devices that still run affected Android versions.

Recommended defensive actions

  • Apply the Android security update tied to the January 2017 bulletin for affected devices.
  • Inventory Android devices and flag those on affected releases listed in the CVE record.
  • Reduce exposure to untrusted or unmanaged app installation where policy allows.
  • Verify remediation on high-value devices and enterprise-managed endpoints after update.
  • Use vendor advisories and NVD detail pages to confirm the exact build or patch level.

Evidence notes

The CVE description states this is an Audioserver information disclosure that can let a local malicious application access data outside its permission level. The NVD vector is CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N with CWE-200. The supplied corpus also shows an Android Security Bulletin dated 2017-01-01 and a CVE publication date of 2017-01-13.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-0398 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-0398

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-0398 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0398

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.