Mandiant FireEye has disclosed the details of a serious information disclosure vulnerability affecting one of the Qualcomm software package widely used. The issue affects devices running Android 5.0 Lollipop and earlier, a significant impact if we consider that more or less 73 percent of Android devices are affected by the vulnerability. The flaw can be exploited by attackers to escalate privileges to the built-in radio user, its permissions higher than the ones normally assigned to third-party apps. Qualcomm has issued a fix by early March and sent the update to various device manufacturers.”]
Source: http://securityaffairs.co/wordpress/47022/mobile-2/qualcomm-software-flaw.html