Impact
Qualcomm’s GPS decoding logic contains an integer overflow that can corrupt memory when processing satellite data files with invalid signature offsets. The overflow can corrupt critical buffers, which in turn may allow an attacker to gain execution control or cause a denial of service. The weakness is identified as CWE‑190 and exhibits a high severity CVSS score of 8.8.
Affected Systems
The vulnerability affects Qualcomm Snapdragon platforms, including fixed‑wireless 5G access platforms and a broad range of mobile chipsets such as Snapdragon 4 Gen 1, 4 Gen 2, 6 Gen 1, 6 Gen 3, 6 Gen 4, 778G+, 782G, 7C, 8 Gen 1, 8 Gen 2, 8 Gen 3, as well as related modem and network modules (e.g., WCD 9340, WCD 9360, WCN 3910). Firmware versions listed as affected in the vendor advisory correspond to the listed CPEs.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is high severity, but the EPSS score is below 1% and the issue is not yet in the KEV catalog, indicating that active exploitation is unlikely at the moment. Attackers would need to supply specially crafted GPS satellite messages or manipulate the firmware’s input streams, a scenario that typically requires physical proximity or compromised data paths. No public exploit is currently documented.
OpenCVE Enrichment