PatchSiren cyber security CVE debrief
CVE-2017-0448 Google CVE debrief
CVE-2017-0448 is an Android information disclosure issue in the NVIDIA video driver. According to the supplied description, a local malicious application could access data outside its permitted scope, which makes the flaw relevant for devices where sensitive data exposure matters even without direct code execution. NVD rates the issue with CVSS 3.0 5.5 (Medium), but the impact can still be significant on affected Android devices because confidentiality is affected.
- Vendor
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-08
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-08
- Advisory updated
- 2026-05-13
Who should care
Android device owners, mobile security teams, OEMs, and administrators responsible for devices that include the NVIDIA video driver, especially systems aligned to the supplied Android 7.1.1 and Linux kernel 3.10 CPE coverage.
Technical summary
The supplied NVD record describes an information disclosure weakness mapped to CWE-200. The CVSS vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N, indicating a local attack that requires user interaction and primarily impacts confidentiality. The record references Android security bulletin guidance and lists affected Android and Linux kernel CPEs in the source corpus.
Defensive priority
Medium-High for exposed Android fleets; prioritize if affected devices may handle sensitive or regulated data.
Recommended defensive actions
- Apply the vendor fix referenced in the Android security bulletin linked from the NVD record.
- Inventory Android devices and builds that include the NVIDIA video driver, with attention to the Android and Linux kernel CPEs listed in the source corpus.
- Confirm that devices are at or beyond the vendor-patched security level associated with the February 2017 Android bulletin.
- Treat unpatched affected devices as confidentiality-risk assets and limit exposure of sensitive data until updates are verified.
- Validate remediation using device security patch level checks and standard mobile fleet compliance reporting.
Evidence notes
This debrief is based only on the supplied NVD record and its official/vendor references. The source corpus states: information disclosure in the NVIDIA video driver, local malicious application access outside permission levels, Android product context, and reference to the Android security bulletin (2017-02-01). NVD lists CVSS 3.0 5.5 and CWE-200. Publication date used here is the CVE publishedAt timestamp (2017-02-08T15:59:01.957Z); the later 2026-05-13 modification timestamp is not treated as the issue date.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-0448 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-0448
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-0448 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0448
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://source.android.com/security/bulletin/2017-02-01.html
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.