CVE-2019-10527: Out-of-bounds Read
u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SMEM address range which could lead to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA4531, QCA6574AU, QCA8081, QCM2150, QCN7605, QCN7606, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA515M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10527?
The severity of CVE-2019-10527 is classified as moderate, as it may lead to memory corruption in affected devices.
How do I fix CVE-2019-10527?
To fix CVE-2019-10527, ensure you apply the latest security patches provided by your device manufacturer as soon as they are available.
Which devices are affected by CVE-2019-10527?
CVE-2019-10527 affects various Qualcomm Snapdragon devices including those running Android and specific Qualcomm firmware versions.
What exploitation methods exist for CVE-2019-10527?
CVE-2019-10527 can be exploited through a compromise in the High Level Operating System (HLOS) that manipulates the Shared Memory (SMEM) partition.
Can CVE-2019-10527 lead to data breaches?
Yes, CVE-2019-10527 could potentially lead to unauthorized access to sensitive data due to memory corruption vulnerabilities.