CVE-2019-14115: Medium severity Google Android vulnerability
u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display session which can result in user reading the secure input while touch is in non-secure domain as secure display is active' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8076, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA515M, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14115?
CVE-2019-14115 is an information disclosure vulnerability that occurs when secure touch is released without clearing the display session, potentially allowing a user to read secure input in a non-secure domain with active secure display.
How severe is CVE-2019-14115?
CVE-2019-14115 has a severity value of 5.5, categorized as high.
Which software is affected by CVE-2019-14115?
CVE-2019-14115 affects Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, and various Qualcomm firmware versions for different products, including Google Android.
Are Qualcomm Apq8009 and Apq8017 vulnerable to CVE-2019-14115?
No, Qualcomm Apq8009 and Apq8017 are not vulnerable to CVE-2019-14115.
Where can I find more information about CVE-2019-14115?
You can find more information about CVE-2019-14115 on the Qualcomm and Android security bulletins for August 2020.