First published: Mon Apr 02 2018(Updated: )
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, and SD 835, in some TrustZone API functions, untrusted pointers can be dereferenced.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm SD210 Firmware | ||
Qualcomm SD 210 Firmware | ||
Qualcomm SD 212 | ||
Qualcomm SD 212 Firmware | ||
Qualcomm SD205 Firmware | ||
Qualcomm SD205 Firmware | ||
Qualcomm SDR425 Firmware | ||
Qualcomm Snapdragon 425 | ||
Qualcomm SD 430 Firmware | ||
Qualcomm SD 430 Firmware | ||
Qualcomm SDM450 Firmware | ||
Qualcomm SDM450 | ||
Qualcomm SD 625 Firmware | ||
Qualcomm Snapdragon 625 | ||
Qualcomm SD650 Firmware | ||
Qualcomm Snapdragon 650 | ||
Qualcomm SD652 Firmware | ||
Qualcomm SD652 Firmware | ||
Qualcomm SD835 Firmware | ||
Qualcomm Snapdragon 835 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9200 is classified as a high severity vulnerability due to the potential for untrusted pointer dereferencing.
To fix CVE-2015-9200, update your device firmware to the latest security patch level after April 5, 2018.
CVE-2015-9200 affects devices running Android before the April 5, 2018 security patch and several Qualcomm Snapdragon chipsets.
The impact of CVE-2015-9200 includes potential exploitation of trust zone APIs leading to unauthorized access to sensitive data.
Not all Qualcomm Snapdragon devices are vulnerable, only those listed with specific firmware versions affected by CVE-2015-9200.