Security Advisory

CVE-2016-3840

9.8
CRITICAL

Vulnerability Description

Conscrypt in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-05 does not properly identify session reuse, which allows remote attackers to execute arbitrary code via unspecified vectors, aka internal bug 28751153.
Published Date August 5, 2016
Official Source NIST NVD Advisory