CVE-2015-9221: Qualcomm Sd 400 Firmware

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400, SD 800, and SD 810, lack of validation of pointers passed by secure apps could lead to an untrusted pointer dereference.

Affected products

  • Qualcomm Sd 400 Firmware: affected versions not specified
  • Qualcomm Sd 800 Firmware: affected versions not specified
  • Qualcomm Sd 810 Firmware: affected versions not specified

Published 2018-04-18. Last modified 2026-06-17.