Permissions, Privileges, and Access Controls in Qualcomm products - CVE-2024-53011
Published: March 3, 2025
Vulnerability identifier: #VU105209
CSH Severity: Low
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-53011
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local privileged application to read and manipulate data.
The vulnerability exists due to improper input validation in Video Analytics and Processing. A local privileged application can read and manipulate data.
Affected software
Snapdragon 8+ Gen 1 Mobile Platform
SXR2330P
SXR2250P
SXR2230P
SXR1230P
SSG2125P
SSG2115P
Snapdragon AR2 Gen 1 Platform
Snapdragon AR1 Gen 1 Platform "Luna1"
Snapdragon AR1 Gen 1 Platform
Snapdragon 8+ Gen 2 Mobile Platform
WCD9370
Snapdragon 8 Gen 3 Mobile Platform
Snapdragon 8 Gen 2 Mobile Platform
Snapdragon 8 Gen 1 Mobile Platform
SM8750P
SM8750
SM8735
SM8650Q
SM8635P
SM8635
WCN7750
WSA8845H
WSA8845
WSA8840
WSA8835
WSA8830
WCN7881
WCN7880
WCN7861
WCN7860
SM8550P
WCN6755
WCN6650
WCN6450
WCD9395
WCD9390
WCD9385
WCD9380
WCD9378
WCD9375
QCA6595
QRB5165N
QMP1000
QCS8550
QCS7230
QCN9274
QCM8550
QCA6696
QCA6688AQ
QCA6595AU
Qualcomm Video Collaboration VC5 Platform
QCA6574A
QCA6574
QCA6564AU
QCA6564
QCA6391
Flight RB5 5G Platform
FastConnect 7800
FastConnect 6900
SA8155
SM7675P
SM7675
SM7635
SM6650
SG8275P
SD 8 Gen1 5G
SC8380XP
SA8195P
SA8155P
FastConnect 6700
SA8150P
SA8145P
SA6155
SA6150P
SA6145P
SA4155P
SA4150P
Robotics RB5 Platform
Samsung Mobile Firmware
WSA8832
QCS8155
QCA6574AU
SA6155P
Google Android
SXR2330P
SXR2250P
SXR2230P
SXR1230P
SSG2125P
SSG2115P
Snapdragon AR2 Gen 1 Platform
Snapdragon AR1 Gen 1 Platform "Luna1"
Snapdragon AR1 Gen 1 Platform
Snapdragon 8+ Gen 2 Mobile Platform
WCD9370
Snapdragon 8 Gen 3 Mobile Platform
Snapdragon 8 Gen 2 Mobile Platform
Snapdragon 8 Gen 1 Mobile Platform
SM8750P
SM8750
SM8735
SM8650Q
SM8635P
SM8635
WCN7750
WSA8845H
WSA8845
WSA8840
WSA8835
WSA8830
WCN7881
WCN7880
WCN7861
WCN7860
SM8550P
WCN6755
WCN6650
WCN6450
WCD9395
WCD9390
WCD9385
WCD9380
WCD9378
WCD9375
QCA6595
QRB5165N
QMP1000
QCS8550
QCS7230
QCN9274
QCM8550
QCA6696
QCA6688AQ
QCA6595AU
Qualcomm Video Collaboration VC5 Platform
QCA6574A
QCA6574
QCA6564AU
QCA6564
QCA6391
Flight RB5 5G Platform
FastConnect 7800
FastConnect 6900
SA8155
SM7675P
SM7675
SM7635
SM6650
SG8275P
SD 8 Gen1 5G
SC8380XP
SA8195P
SA8155P
FastConnect 6700
SA8150P
SA8145P
SA6155
SA6150P
SA6145P
SA4155P
SA4150P
Robotics RB5 Platform
Samsung Mobile Firmware
WSA8832
QCS8155
QCA6574AU
SA6155P
Google Android
How to mitigate CVE-2024-53011
Install security update from vendor's website.
Samsung Mobile Firmware - update to SMR-APR-2025
Google Android - addressed in versions 12L 2025-03-05, 12 2025-03-05, 13 2025-03-05, 14 2025-03-05, 15 2025-03-05
Google Android - addressed in versions 12L 2025-03-05, 12 2025-03-05, 13 2025-03-05, 14 2025-03-05, 15 2025-03-05