Qualcomm Snapdragon 855 modem code flaw exposed Android smartphones to possible snooping

A heap overflow vulnerability in Qualcomm’s Snapdragon 855 system-on-chip modem firmware, used in Android devices, could be exploited by baddies to run arbitrary code on unsuspecting users’ devices, according to Check Point. The software bug, tracked as CVE-2020-11292, can be abused to trigger a heap overflow in devices that use a Qualcomm Mobile Station Modem (MSM) chip, thanks to some in-depth jiggery-pokery in the Qualcomm MSM Interface (QMI) voice service API.

Read full article on The Register

 


Date:

Categorie(s):