CVE-2018-13927: High severity android vulnerability
Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image loading in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, QCS404, QCS605, SD 410/12, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-13927?
CVE-2018-13927 refers to a vulnerability where debug policy with an invalid signature can be loaded even when the debug policy functionality is disabled in certain Qualcomm products.
Which software and devices are affected by CVE-2018-13927?
CVE-2018-13927 affects Google Android, Qualcomm Mdm9206 Firmware, Qualcomm Mdm9650 Firmware, and several other Qualcomm products.
What is the severity of CVE-2018-13927?
CVE-2018-13927 has a severity rating of 7.8 (out of 10), which is considered critical.
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-13927?
The CWE ID for CVE-2018-13927 is CWE-287, which refers to an Improper Authentication vulnerability.
Where can I find more information about CVE-2018-13927?
You can find more information about CVE-2018-13927 in the Android Security Bulletin for June 2019 and the Qualcomm Product Security Bulletins.