Google has patched a high-severity vulnerability that has been around for five years. The vulnerability, CVE-2016-2060, affects Android versions 4.3 and earlier that use the software package maintained by mobile chipmaker Qualcomm. The issue was first introduced in 2011 when Qualcomm released a set of new APIs (Application Programming Interfaces) for a network manager system service to the Android Open Source Project (AOSP) The issue has also been confirmed on devices running Android 5.0 Lollipop and Android 4.4 KitKat.
Source: https://thehackernews.com/2016/05/android-hacking.html