CVE-2016-6586: Symantec Norton Mobile Security

Low severity, CVSS 3.7. EPSS: 1.3% chance of exploitation in the next 30 days.

A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially crafted JavaScript to add arbitrary URLs to the URL whitelist.

Affected products

  • Symantec Norton Mobile Security: before 3.16 (fixed in 3.16)

Published 2020-01-08. Last modified 2026-06-17.