Android devices are vulnerable to an attack that could allow a remote user to inject malicious code into an unencrypted traffic stream. The flaw, CVE-2016-5696, exists in versions 4.7 and prior of the Linux kernel and was patched in July. Google is aware of the problem, and a related patch is being prepared. The attack doesn’t work against encrypted traffic streams, so until Android gets patched, the flaw can be mitigated by using a VPN. An attacker could use the flaw to force a connection to terminate or infer what websites a person is visiting.”]
Source: https://www.healthcareinfosecurity.com/android-vulnerable-to-serious-tcp-flaw-in-linux-a-9353

