CVE-2016-10239: Google Android

High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.

In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel due to improper input validation an integer overflow vulnerability leading to a buffer overflow could potentially occur and a buffer over-read vulnerability could potentially occur.

Affected products

Published 2017-05-16. Last modified 2026-06-17.