CVE-2015-6639
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted...
- Published
- Jan 6, 2016
- Updated
- Feb 13, 2025
- Assigning CNA
- google_android
- Evidence observed
- May 2, 2016
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:CModerate · next 30 days
- Percentile
- 95.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875.
Sources
3- ExtractKeyMasterExploit
Exploit that extracts Qualcomm's KeyMaster keys using CVE-2015-6639 and CVE-2016-2431
- cve-2015-6639Exploit
QSEE Privilege Escalation Exploit using PRDiag* commands (CVE-2015-6639)
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.