CVE-2015-9031
Description
In Android devices from CAF, HDCP exposes a TZ memory address to HLOS, leading to a low-severity information disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
In Android devices from CAF, HDCP exposes a TZ memory address to HLOS, leading to a low-severity information disclosure.
Vulnerability
In all Android releases from CAF (Code Aurora Forum) using the Linux kernel, the HDCP (High-bandwidth Digital Content Protection) implementation exposes a TZ (TrustZone) memory address to the HLOS (High-Level Operating System) [1]. This happens due to improper handling of memory addresses between the secure and non-secure worlds. All affected versions are listed in the Android Security Bulletin—June 2017 [1].
Exploitation
An attacker with local access to the device and the ability to interact with the HLOS can read the exposed TZ memory address [1]. No special permissions or user interaction beyond normal device usage is required, as the information is leaked through the standard HDCP interface.
Impact
Successful exploitation allows an attacker to obtain a TZ memory address, which may reveal information about the secure memory layout [1]. This is a low-severity information disclosure that does not directly enable code execution or privilege escalation without further vulnerabilities.
Mitigation
Android partners were notified of the issue and updates were included in the June 2017 Android security patch level [1]. Users should apply the security update from their device manufacturer. No workarounds are available for unpatched devices.
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Qualcomm, Inc./All Qualcomm productsv5Range: All Android releases from CAF using the Linux kernel
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/98874nvdThird Party AdvisoryVDB Entry
- source.android.com/security/bulletin/2017-06-01nvdVendor Advisory
- www.securitytracker.com/id/1038623nvd
News mentions
0No linked articles in our index yet.