Double Free in Qualcomm products - CVE-2022-25750
Published: October 3, 2022
Vulnerability details
The vulnerability allows an attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within Bluetooth HOST while music playback and calls over bluetooth headset. An attacker with physical proximity to device can trigger a double free error and execute arbitrary code on the target system.
Affected software
SG8275
SG8275P
SM8550
WCD9380
WCD9385
WCD9390
WCD9395
WCN6855
WCN6856
WCN7850
WCN7851
WSA8840
WSA8845
WSA8845H