Qualcomm Automotive Platform Nonce Reuse Vulnerability in License Data Encryption

Vulnerability

A cryptographic vulnerability has been identified in the Qualcomm Automotive Platform, which may arise during the encryption of license data. This issue involves the reuse of a nonce and key pair, potentially compromising the integrity of the encrypted information.

Impact

Exploitation of this vulnerability could lead to cryptographic issues, potentially allowing for unauthorized decryption or manipulation of license data.

Remediation

Qualcomm has notified customers about this vulnerability and is actively sharing patches. Instructions for applying the patch can be found in the January 2026 Qualcomm Security Bulletin.

Added: Jan 7, 2026, 6:29 PM
Updated: Jan 7, 2026, 6:29 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
5.0
exploitability
3.3
remediation
0.0
relevance
1.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.