While accessing SafeSwitch services, third party can manipulate a given device and perform unauthorized operation due to lack of checking of same state transitions in Snapdragon Automobile, Snapdragon Mobile in version MSM8996AU, SD 410/12, SD 617, SD 650/52, SD 810, SD 820, SD 820A
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://source.android.com/security/bulletin/2018-09-01#qualcomm-closed-source-components | third party advisory |
https://www.qualcomm.com/company/product-security/bulletins | vendor advisory |