CVE-2016-5860: Google Android

High severity, CVSS 7.0. EPSS: 0.6% chance of exploitation in the next 30 days.

In an audio driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very large length, an integer overflow could occur followed by a heap buffer overflow.

Affected products

Published 2017-08-16. Last modified 2026-06-17.