Impact
An out‑of‑bounds write occurs in the Qualcomm Snapdragon camera driver when parsing JPEG commands; the driver performs unaccounted writes to its buffer during validation checks. This memory corruption can produce unexpected behavior such as application crashes or corrupted image data. The vulnerability is limited to integrity and availability problems and is not documented to enable remote code execution.
Affected Systems
All Qualcomm Snapdragon devices that include the affected camera driver are considered potentially vulnerable. No specific model or firmware version details are available, so the entire Snapdragon platform containing this driver is at risk until a vendor patch is released.
Risk and Exploitability
The CVSS score of 5.3 combined with an EPSS score of less than 1% and the absence from the CISA KEV catalog indicate that widespread exploitation is currently unlikely. The most probable attack vector is local or privileged, originating from applications that send JPEG data to the driver. If an attacker can inject crafted JPEG commands and has sufficient privileges to invoke the driver, they could induce memory corruption, but the overall risk remains moderate under current evidence.
OpenCVE Enrichment