Impact
The vulnerability is an out‑of‑bounds read (CWE‑125) triggered when Snapdragon devices process unverified data from a neighboring system, causing a transient denial‑of‑service by reading outside allocated memory. This can result in application crashes or device instability, compromising availability. The flaw does not suggest any direct information leakage or other impact.
Affected Systems
Qualcomm Snapdragon devices are affected. The advisory does not specify affected firmware or hardware revisions, so all current Snapdragon implementations that accept inter‑system data are potentially vulnerable until the vendor issues a fix.
Risk and Exploitability
With a CVSS score of 7.9, the flaw presents a high severity rating. The EPSS score indicates a very low exploitation probability (<1 %), and it is not listed in CISA KEV, suggesting no publicly known exploit currently. The attack vector is inferred to be local or nearby systems that can send malicious data before the Snapdragon device processes it; the flaw does not appear to be exploitable remotely over the internet. Until a patch is released, the primary risk is local denial of service which can affect devices connected in the same physical or logical network segment.
OpenCVE Enrichment