CVE-2015-9162 is a critical vulnerability affecting Qualcomm Snapdragon Mobile processors (SD 410/12, 617, 650/52, 800, 808, 810) in Android devices prior to the 2018-04-05 security patch. It stems from a memory allocation error in the "Certificate_CreateWithBuffer" function within the QSEE app TQS, leading to a use-after-free condition (CWE-476). With a CVSS score of 9.8, this vulnerability is critical, allowing for unauthenticated remote exploitation with high impact on confidentiality, integrity, and availability. Despite its high severity and significant community discussion, there is no known active exploitation, nor are there public exploit modules available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:sd_410_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:sd_412_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:sd_617_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:sd_650_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:sd_652_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.