First published: Mon Apr 02 2018(Updated: )
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 835, SD 845, and SD 850, vendor specific opcodes may not have any packet length validation leading to buffer over-reads.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm SD835 Firmware | ||
Qualcomm Snapdragon 835 | ||
Qualcomm SDA845 Firmware | ||
Qualcomm SD845 | ||
Qualcomm SD850 Firmware | ||
Qualcomm SD850 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10460 is considered a high severity vulnerability due to potential buffer over-reads.
To fix CVE-2016-10460, you should update the affected Qualcomm Snapdragon firmware to a version released after the April 2018 security patch.
CVE-2016-10460 affects devices using Qualcomm Snapdragon 835, 845, and 850 chipsets with specific firmware versions prior to the April 2018 patch.
The risks of CVE-2016-10460 include exposure to unauthorized information, as the vulnerability allows for buffer over-reads.
CVE-2016-10460 may be exploitable remotely under specific circumstances due to the lack of packet length validation.