Impact
Memory corruption occurs when the primary bootloader parses a specially crafted ELF file. The flaw can allow an attacker to overwrite critical bootloader data, potentially leading to arbitrary code execution with system‑level privileges.
Affected Systems
Qualcomm Snapdragon platforms are affected. Specific models or firmware revisions are not listed, so any Snapdragon‑based device that uses the primary bootloader with the affected code may be vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates significant severity. The EPSS score is not available, so exploitation probability is unknown; the vulnerability is not currently listed in CISA KEV. The attack vector is inferred to require delivering a crafted ELF file during the bootloader’s loading phase, such as during a firmware update or manual flashing, implying a close or physical access scenario.
OpenCVE Enrichment