PatchSiren cyber security CVE debrief
CVE-2017-0406 Google CVE debrief
CVE-2017-0406 describes a memory-corruption flaw in Android's Mediaserver processing path for libhevc. Google characterized it as a remote code execution issue, while NVD rates it 7.8 HIGH with a CVSS 3.0 vector indicating local access and user interaction are required.
- Vendor
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-08
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-08
- Advisory updated
- 2026-05-13
Who should care
Android fleet operators, mobile security teams, and device owners running affected Android builds should care, especially where untrusted media files may be opened or processed on 6.0, 6.0.1, 7.0, 7.1.0, or 7.1.1 devices.
Technical summary
The vulnerability affects the libhevc library used by Android Mediaserver during media file and data processing. NVD identifies CWE-119 and a CVSS 3.0 vector of AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating that successful exploitation can have full confidentiality, integrity, and availability impact within the Mediaserver process context. The CVE description says a specially crafted file could trigger memory corruption during parsing.
Defensive priority
High. This affects media parsing in a privileged Android process and can lead to code execution or device compromise impact within Mediaserver. Prioritize patching and update compliance on any exposed Android 6.x and 7.x devices.
Recommended defensive actions
- Apply the Android security update that addresses CVE-2017-0406, or a later cumulative update, on all affected devices.
- Inventory managed Android devices for vulnerable versions referenced by NVD and the CVE description, including Android 6.0, 6.0.1, 7.0, 7.1.0, and 7.1.1.
- Restrict or closely control handling of untrusted media files on affected devices until updates are confirmed.
- Use MDM or compliance tooling to enforce minimum patch levels and remove unsupported Android builds from managed fleets.
- Treat unexpected crashes or anomalies in Mediaserver or libhevc as security-relevant and investigate them promptly.
Evidence notes
The CVE record and NVD detail confirm the Android platform scope, the libhevc/Mediaserver impact, and the CWE-119 classification. The NVD record also lists vulnerable CPEs for Android 6.0, 6.0.1, 7.0, 7.1.0, and 7.1.1, while the CVE description explicitly names 6.0, 6.0.1, 7.0, and 7.1.1. The vendor advisory reference points to the Android security bulletin dated 2017-02-01. CVE published date used here is 2017-02-08, per the supplied timeline.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-0406 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-0406
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-0406 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0406
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://source.android.com/security/bulletin/2017-02-01.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.