Impact
The flaw is a buffer over‑read that occurs when a pointer is reused after it has been freed. This can allow an attacker to read memory that lies beyond the intended bounds, potentially exposing sensitive information. The weakness is classified as CWE‑126: Buffer Over-read.
Affected Systems
Qualcomm Snapdragon devices are affected. No specific firmware or software version numbers are supplied in the advisory, so all current Snapdragon implementations remain at risk until a fix is applied.
Risk and Exploitability
The CVSS score of 7.3 indicates a moderate to high severity, while the EPSS score of less than 1% shows that the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly described, but it is inferred that an attacker would need to trigger the OOBM feature in a context where the pointer reuse is observable, possibly requiring local code execution or privileged access to firmware functions.
OpenCVE Enrichment