Multiple Kernel Vulnerabilities Affecting All Qualcomm Devices
ID: 31ad4189-fb45-5a3b-b1f0-2d1cd2258939
STIX ID: report--31ad4189-fb45-5a3b-b1f0-2d1cd2258939
Feed Name: Zimperium Blog
Threat Score
Zimperium's blog describes two critical Qualcomm QSEECOM kernel vulnerabilities (a use-after-free CVE-2019-14040 and a race condition CVE-2019-14041) that can enable an unprivileged app to gain full root/kernel privileges on Android devices with Qualcomm chipsets; the post provides technical analysis, exploitation scenarios, public proof-of-concept code, and a disclosure timeline noting Qualcomm's February 2020 fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
