CVE-2018-11935: Input Validation
Improper input validation might result in incorrect app id returned to the caller Instead of returning failure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9607, MDM9650, MDM9655, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM630, SDM660, SXR1130.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11935?
CVE-2018-11935 is a vulnerability that results in incorrect app id returned to the caller in certain Qualcomm and Google Android products, potentially allowing unauthorized access to sensitive information.
Which products are affected by CVE-2018-11935?
CVE-2018-11935 affects various Qualcomm products such as Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, and Snapdragon Mobile in certain versions. It also affects Google Android.
What is the severity of CVE-2018-11935?
The severity of CVE-2018-11935 is rated as high, with a severity value of 5.3.
How can I fix CVE-2018-11935?
To fix CVE-2018-11935, it is recommended to apply the necessary security patches and updates provided by Qualcomm and Google Android. It is also important to regularly update your software to ensure you have the latest security fixes.
Where can I find more information about CVE-2018-11935?
More information about CVE-2018-11935 can be found in the official Android Security Bulletin for February 2019, as well as the provided references.