CVE-2018-11951: Qualcomm Sd 845 Firmware

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper access control in core module lead XBL_LOADER performs the ZI region clear for QTEE instead of XBL_SEC in Snapdragon Mobile in version SD 845, SD 850.

Affected products

  • Qualcomm Sd 845 Firmware: affected versions not specified
  • Qualcomm Sd 850 Firmware: affected versions not specified

Published 2018-10-26. Last modified 2026-06-17.