CVE-2016-3887: Google Android
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
providers/settings/SettingsProvider.java in Android 7.0 before 2016-09-01 does not properly enforce the DISALLOW_CONFIG_VPN setting, which allows attackers to bypass an intended always-on VPN state via a crafted application, aka internal bug 29899712.
Affected products
- Google Android: version 7.0 only
Published 2016-09-11. Last modified 2026-06-17.