Use After Free in Qualcomm products - CVE-2022-33225
Published: February 7, 2023
Vulnerability identifier: #VU71964
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-33225
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to improper input validation in Trusted Application Environment. A local privileged application can execute arbitrary code.
Affected software
SD429
WSA8815
WSA8810
WCN6851
WCN6850
WCN3660B
WCN3620
WCN3610
WCD9380
WCD9340
SDXR2 5G
SDX55M
SD870
SD865 5G
Qualcomm215
QCA6574A
QCA6564AU
QCA6564A
QCA6436
QCA6426
QCA6391
QCA6390
MDM9628
Pixel
SDM429W
APQ8096AU
SD210
SD205
QCA6574AU
MSM8996AU
WSA8815
WSA8810
WCN6851
WCN6850
WCN3660B
WCN3620
WCN3610
WCD9380
WCD9340
SDXR2 5G
SDX55M
SD870
SD865 5G
Qualcomm215
QCA6574A
QCA6564AU
QCA6564A
QCA6436
QCA6426
QCA6391
QCA6390
MDM9628
Pixel
SDM429W
APQ8096AU
SD210
SD205
QCA6574AU
MSM8996AU
How to mitigate CVE-2022-33225
Install security update from vendor's website.
Pixel - update to 2023-02-05