ZeroHour
CyberScooppublished ()ingested @shanvav

Flaws in Qualcomm chips could allow snooping, Check Point finds

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-11201
+1 in the same advisory: …11202
Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consu

Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM6125, QCS410, QCS603, QCS605, QCS610, QCS6125, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SDA640, SDA845, SDM640, SDM830, SDM845, SDX50M, SDX55, SDX55M, SM6125, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM8150, SM8150P

NVD description · AI analysis pending
7.82% PoC
  • qualcomm qcm6125 firmware
  • qualcomm qcs410 firmware
  • qualcomm qcs603 firmware
  • +1 more
CVE-2020-11206
Possible buffer overflow in Fastrpc while handling received parameters due to lack of validation on input parameters' in Snapdragon Auto, Snapdragon Compute, Sn

Possible buffer overflow in Fastrpc while handling received parameters due to lack of validation on input parameters' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8098, MSM8998, QCM4290, QCM6125, QCS410, QCS4290, QCS610, QCS6125, QSM8250, QSM8350, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155, SA8155P, SA8195P, SC7180, SDA640, SDA660, SDA845, SDA855, SDM640, SDM660, SDM830, SDM845, SDM850, SDX50M, SDX55, SDX55M, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6150, SM6150P, SM6250, SM6250P, SM6350, SM7125, SM7150, SM7150P, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR2130, SXR2130P

NVD description · AI analysis pending
7.82% PoC
  • qualcomm apq8098 firmware
  • qualcomm msm8998 firmware
  • qualcomm qcm4290 firmware
  • +1 more
CVE-2020-11208
+1 in the same advisory: …11209
Out of Bound issue in DSP services while processing received arguments due to improper validation of length received as an argument' in SD820, SD821, SD820, QCS

Out of Bound issue in DSP services while processing received arguments due to improper validation of length received as an argument' in SD820, SD821, SD820, QCS603, QCS605, SDA855, SA6155P, SA6145P, SA6155, SA6155P, SD855, SD 675, SD660, SD429, SD439

NVD description · AI analysis pending
7.8
group max
2% PoC
  • qualcomm sd820 firmware
  • qualcomm sd821 firmware
  • qualcomm qcs603 firmware
  • +1 more
Full article649 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Qualcomm Technologies Snapdragon chips have over 400 vulnerabilities, some of which could allow hackers to spy on users’ GPS location.

chip flaw
(Jeff Sass / Flickr)

Software flaws in millions of smartphones used throughout the world could give hackers a gateway into users’ personal data.

More than 400 vulnerabilities in chips used in approximately 40% of the world’s cellphones and devices could allow hackers to spy on users’ GPS location and microphones in real-time, according to new Check Point research.

The vulnerable units, Digital Signal Processor units or DSP chips made by Qualcomm Technologies, specifically Qualcomm Snapdragon DSP chips, impact popular cellphones and devices from Samsung, LG, Xiaomi, and Google are vulnerable, according to researchers.

DSP chips, made up of software and hardware, are designed to enhance charging, audio features, and multimedia activities. But these flaws are a reminder that as ubiquitous as chips are in popular devices, vulnerabilities abound. The Spectre and Meltdown vulnerabilities, discovered by Google’s Project Zero two years ago, affected nearly every modern computer chip, for instance.

In a statement shared with CyberScoop, Qualcomm said it has seen no evidence that hackers have exploited the vulnerabilities, and that it is working with original equipment manufacturers to remedy the issue.

“Providing technologies that support robust security and privacy is a priority for Qualcomm,” a Qualcomm spokesperson said. “[W]e worked diligently to validate the issue and make appropriate mitigations available to OEMs…We encourage end users to update their devices as patches become available and to only install applications from trusted locations such as the Google Play Store.”

Some of the vulnerabilities could enable attackers to spy on vulnerable users’ photos, videos, calls, GPS location, and even access their microphones, according to Check Point. Others could allow them to force the phone to be unresponsive, by making all of the data stored on the phone permanently unavailable, including contacts, photos, and videos, Check Point security researcher Slava Makkaveev said. Some of the vulnerabilities would also enable attackers to hide malware in their campaigns, according to Makkaveev.

The vulnerabilities do not appear to affect iPhones. But in Android devices, if there is one original equipment manufacturer, or OEM, that has a vulnerable Snapdragon DSP the vulnerability can essentially spread to others, according to Makkaveev.

“It’s possible to run a library intended for one device, for example Chinese Xiaomi, on any other device, for example Samsung,” Makkaveev will say in his presentation at the DEF CON security conference Friday. “This means that a vulnerability discovered in one OEM’s library compromises all Snapdragon-based Android devices.”

Qualcomm has notified multiple vendors of the vulnerabilities, which have been given several CVE numbers, including, CVE-2020-11201, CVE-2020-11202, CVE-2020-11206, CVE2020-11207, CVE-2020-11208, and CVE-2020-11209.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/400-vulnerabilities-qualcomm-snapdragon-chips-check-point-def-con-2020/