CVE-2016-11030: Google Android

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) (with Hrm sensor support) software. The sysfs of the MAX86902 sensor driver does not prevent concurrent access, leading to a race condition and resultant heap-based buffer overflow. The Samsung ID is SVE-2016-7341 (December 2016).

Affected products

  • Google Android: version 4.4 only; version 5.0 only; version 5.1 only; version 6.0 only

Published 2020-04-07. Last modified 2026-06-17.