PatchSiren cyber security CVE debrief
CVE-2017-0413 Google CVE debrief
CVE-2017-0413 is an information disclosure vulnerability in AOSP Messaging that could let a local malicious application bypass Android’s app-isolation protections and access data it should not be able to read. NVD rates the issue with CVSS 3.0 5.5 (Medium), but the vulnerability description also characterizes the impact as High because it can expose application data.
- Vendor
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-08
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-08
- Advisory updated
- 2026-05-13
Who should care
Android security teams, mobile device administrators, and organizations that allow third-party apps on devices running Android 6.0, 6.0.1, 7.0, or 7.1.1. It is most relevant where local malicious apps are a realistic risk.
Technical summary
The NVD record describes CVE-2017-0413 as a local information disclosure issue in AOSP Messaging. The CVSS vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N, indicating a local attack that requires user interaction, no privileges, unchanged scope, and high confidentiality impact. NVD maps the weakness to CWE-200. The affected Android versions listed in the record are 6.0, 6.0.1, 7.0, 7.1.0, and 7.1.1.
Defensive priority
Medium
Recommended defensive actions
- Prioritize vendor-provided Android security updates for affected devices.
- Inventory devices running Android 6.0 through 7.1.1 and confirm they are on a patched security level.
- Treat untrusted or sideloaded Android apps as a meaningful risk factor on affected devices.
- Review the Android security bulletin and related vendor advisory references for remediation guidance.
- Monitor for any signs that messaging-related app data may be exposed on unmanaged or outdated devices.
Evidence notes
This debrief is based on the NVD CVE record and its vendor references. The record states the issue is an information disclosure vulnerability in AOSP Messaging, lists affected Android versions 6.0 through 7.1.1, assigns CVSS 3.0 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N with score 5.5, and identifies CWE-200. The source corpus includes a vendor advisory reference from source.android.com and no KEV entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-0413 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-0413
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-0413 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0413
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://source.android.com/security/bulletin/2017-02-01.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.