Impact
The vulnerability is an untrusted pointer dereference that can cause memory corruption during the processing of rear sensor IOCTL calls. This flaw allows a malicious actor to write arbitrary data to memory, potentially leading to program instability, denial of service, or, in worst cases, execution of arbitrary code if the corrupted memory lies within executable or critical control structures.
Affected Systems
Qualcomm Snapdragon platforms that incorporate rear camera sensors are affected. No specific firmware or device model details are provided, so any system that uses the referenced camera driver could be vulnerable.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate severity, while the EPSS score of less than 1% suggests the likelihood of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog. The attack likely requires a local or privileged attacker who can invoke the vulnerable IOCTL interface; there is no publicly disclosed remote exploitation vector. Based on the description, it is inferred that an attacker would need to supply a crafted IOCTL command to trigger the memory corruption.
OpenCVE Enrichment