Impact
A memory corruption flaw is introduced when Snapdragon video decoding processes decode statistics without correctly validating an offset against the structure size. The insufficient check allows a crafted offset value to write beyond the intended bounds, which can corrupt adjacent memory and, depending on the execution context, may enable arbitrary code execution or cause the system to crash. The flaw is classified under CWE-787 and is reflected in the CVSS base score of 7.8.
Affected Systems
The vulnerability affects Qualcomm Snapdragon devices; the vendor list indicates Qualcomm, Inc. as the affected manufacturer. No specific product models or firmware revisions are disclosed, and the CVE data does not provide version ranges for affected hardware or software. Administrators should verify which Snapdragon-based devices are in use and check for vendor‑released security updates or patches.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, yet the EPSS score is listed as less than 1%, suggesting a low probability of exploitation at the current time. The vulnerability is not listed in the CISA KEV catalog, further indicating limited evidence of exploitation. The likely attack vector is inferred to involve a malicious media file or stream that forces the crash or code execution during decoding, but the CVE description does not explicitly state the conditions required to trigger the flaw.
OpenCVE Enrichment