Impact
A buffer over-read occurs in the WinBlast driver when the output buffer size is not validated correctly. The flaw qualifies as CWE-126 and allows the driver to read beyond the intended memory boundary, which can lead to memory corruption, potential data leakage, or a denial of service if the driver crashes.
Affected Systems
Qualcomm Snapdragon platforms and associated firmware, including Snapdragon 460, 662, 7c+, 8c, 8cx, 8cx Gen 3, 8cx Gen 5 and other Qualcomm chipsets such as WCD9340, WCD9375, and WCN3988 that use the WinBlast driver, are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The probability of exploitation in the wild is estimated to be lower than 1 percent, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation would likely require local or privileged access to the device and could result in sensitive data exposure or system instability.
OpenCVE Enrichment