CVE-2016-11046: Google Android

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered on Samsung mobile devices with JBP(4.3), KK(4.4), and L(5.0/5.1) software. Because of a misused whitelist, attackers can reach the radio layer (aka RIL or RILD) to place calls or send SMS messages. The Samsung ID is SVE-2016-5733 (May 2016).

Affected products

  • Google Android: version 4.3 only; version 4.4 only; version 5.0 only; version 5.1 only

Published 2020-04-07. Last modified 2026-06-17.