CVE-2015-9110: Input Validation
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, no address argument validation is performed on calls to the qseegetsecurestate syscall.
Affected Software
Event History
Frequently Asked Questions
Which devices are in scope?
The issue affects Android devices with a security patch level earlier than 2018-04-05 that use the listed Qualcomm Snapdragon Automobile or Snapdragon Mobile platforms: SD 425, 430, 450, 625, 650/652, 820, or 820A.
Does exploitation require authentication or user interaction?
No. The CVSS vector indicates network attack access, low attack complexity, no privileges required, and no user interaction.
What is the impact if exploited?
The CVSS vector rates confidentiality, integrity, and availability impact as high, with an overall critical score of 10.0.
How can I determine whether a device is affected?
Check the device's Android security patch level and its Qualcomm Snapdragon platform. Devices on an affected platform with a patch level earlier than 2018-04-05 are in scope.