Impact
Memory corruption occurs when the fingerprint trusted application processes malformed request parameters. The vulnerability can lead to overwritten memory and possible arbitrary code execution or denial of services. This weakness is a classic buffer overflow, classified as CWE‑120.
Affected Systems
The affected product is Qualcomm’s Snapdragon platform, specifically the fingerprint trusted application component. No specific firmware or build versions are listed, so any Snapdragon device that includes the unpatched fingerprint TA is potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. EPSS data is not available, making exploitation probability unclear, and the vulnerability is not listed in the CISA KEV catalogue. Attack vectors are not explicitly stated in the advisory; however, the likely attack path involves an attacker supplying crafted data to the fingerprint TA, which may be local or rely on elevated privileges. Given the lack of mitigation details, the risk remains elevated pending a patch.
OpenCVE Enrichment