CVE-2016-7990: Google Android

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP messages (within WAP Push SMS messages) leading to a heap corruption that can result in Denial of Service and potentially remote code execution, a subset of SVE-2016-6542.

Affected products

  • Google Android: version 4.2.2 only; version 4.3 only; version 4.3.1 only; version 4.4 only; version 4.4.1 only; version 4.4.2 only; …

Published 2016-10-31. Last modified 2026-06-17.