OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bug 27371173.
2016-05-09T10:59:40.643
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.0 (HIGH)
AV:N/AC:H/Au:N/C:C/I:C/A:C
4.9
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | android | 6.0 | Yes | |
| Operating System | android | 6.0.1 | Yes |