CVE-2016-3938: Google Android

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

drivers/video/msm/mdss/mdss_mdp_overlay.c in the Qualcomm video driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 30019716 and Qualcomm internal bug CR 1049232.

Affected products

  • Google Android: up to and including 7.0

Published 2016-10-10. Last modified 2026-06-17.