An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an applications signature can be bypassed during installation. The Samsung ID is SVE-2016-5923 (June 2016).
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Android | 5.0 (including) | 5.0 (including) | |
| Android | 5.1 (including) | 5.1 (including) | |
| Android | 6.0 (including) | 6.0 (including) |