CPATH-2026-0014 · Smart glasses / AR

HoloLens Broadcom Wi-Fi over-the-air RCE/DoS (ADV190017: CVE-2019-9501/9503)

A dominant device-control safety path connects the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Dominant pathDevice-control safety

This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Safety · Dominant path

Device-control safety

Compromise of a head-worn MR display with cameras and live spatial mapping reduces safety margin and can influence what the wearer perceives as real (mid-use).

CRITICAL
  1. accessSource-backed

    Proximity or local access

    Wi-Fi radio proximity, unauthenticated, no association or victim physical access (adjacent radio range).

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    Driver and kernel compromise crosses radio to device to perception and safety boundaries and is a reusable bridge.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Credible safety consequence

    Compromise of a head-worn MR display with cameras and live spatial mapping reduces safety margin and can influence what the wearer perceives as real (mid-use).

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Compromise of a head-worn MR display with cameras and live spatial mapping reduces safety margin and can influence what the wearer perceives as real (mid-use).

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Recovery requires installing the vendor update on each affected headset and validating normal wireless operation.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

Wi-Fi radio proximity, unauthenticated, no association or victim physical access (adjacent radio range).

Source-backedNVD
Execution complexityEC 1
Narrow or timing-dependent technique

Reliable heap-overflow remote code execution is exploit-dependent, fragile and timing-sensitive (denial of service is easy, code execution is hard).

Source-backedNVD
ExposureEX 1
Execution effort limits exposure

The interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 3
Credible safety consequence

Compromise of a head-worn MR display with cameras and live spatial mapping reduces safety margin and can influence what the wearer perceives as real (mid-use).

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

Code execution exposes camera and spatial-map and live-sensor world-model state and can affect rendered-environment integrity.

Model inference
AuthorityAT 3
Administrative or command authority

Native code execution in the wireless driver reaches kernel or service-level device authority, but not the signing or firmware-update root.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Driver and kernel compromise crosses radio to device to perception and safety boundaries and is a reusable bridge.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The over-the-air exploit can be reused against HoloLens devices that contain the affected Broadcom wireless component.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

The code-execution attempt must be made within Wi-Fi range of each target headset rather than through a remote fleet channel.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Recovery requires installing the vendor update on each affected headset and validating normal wireless operation.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Compromise of a head-worn MR display with cameras and live spatial mapping reduces safety margin and can influence what the wearer perceives as real (mid-use).

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:1/EX:1/PH:3/DP:4/AT:3/CH:4/SR:4/SX:2/OR:3/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Recovery · Supporting path

Device availability and recovery

Crashing the head-worn display interrupts the wearer’s live workflow and visual overlay, but does not itself create persistent harm or dangerous actuation.

HIGH
  1. accessSource-backed

    Proximity or local access

    Wi-Fi proximity, unauthenticated, no physical access.

    EvidenceNVD

  2. boundaryModel inference

    One cross-boundary bridge

    Crosses radio to device boundary but is not a reusable cross-domain authority bridge on its own.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Operational safety effect

    Crashing the head-worn display interrupts the wearer’s live workflow and visual overlay, but does not itself create persistent harm or dangerous actuation.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device availability and recovery

    Crashing the head-worn display interrupts the wearer’s live workflow and visual overlay, but does not itself create persistent harm or dangerous actuation.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Device reboots and recovers.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

Wi-Fi proximity, unauthenticated, no physical access.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Crafted Wi-Fi frames can reliably interrupt service with one short exchange; this path does not require the harder code-execution chain.

Source-backedNVD
ExposureEX 2
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Crashing the head-worn display interrupts the wearer’s live workflow and visual overlay, but does not itself create persistent harm or dangerous actuation.

Model inference
Data / perceptionDP 0
No data consequence

The availability path disrupts headset operation without independently exposing sensitive user data.

Model inference
AuthorityAT 2
Bounded function authority

Bounded availability impact of the device and component, no authority gain.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

Crosses radio to device boundary but is not a reusable cross-domain authority bridge on its own.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

Identical frame payload reusable against any affected Broadcom-driver unit (shared component).

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

The attacker must be within Wi-Fi radio range of each HoloLens, so interruption remains one nearby device at a time.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Device reboots and recovers.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandHIGH
  2. No adjustment

    The HIGH base band remains final because no separate cap or systemic uplift applies. Crashing the head-worn display interrupts the wearer’s live workflow and visual overlay, but does not itself create persistent harm or dangerous actuation.

  3. Final candidate bandHIGH
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:2/EC:4/EX:2/PH:2/DP:0/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the safety transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 8.3 HIGHNVD (CVE-2019-9500)
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
v3.1 · 7.9 HIGHCERT/CC via NVD (CVE-2019-9500)
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
v3.1 · 8.8 HIGHNVD (CVE-2019-9501)
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
v3.1 · 7.9 HIGHCERT/CC via NVD (CVE-2019-9501)
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
v3.1 · 8.8 HIGHNVD (CVE-2019-9502)
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
v3.1 · 7.9 HIGHCERT/CC via NVD (CVE-2019-9502)
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
v3.1 · 8.3 HIGHNVD (CVE-2019-9503)
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
v3.1 · 7.9 HIGHCERT/CC via NVD (CVE-2019-9503)
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses HoloLens Broadcom Wi-Fi over-the-air RCE/DoS (ADV190017: CVE-2019-9501/9503) at CRITICAL — the worst of 2 risk paths (safety). The dominant consequence is influence over a safety-relevant actuation.

Vulnerability

HoloLens Broadcom Wi-Fi over-the-air RCE/DoS (ADV190017: CVE-2019-9501/9503). Reported attack vector: ADJACENT_NETWORK (Wi-Fi radio proximity, unauthenticated).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYCRITICAL

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:1/EX:1/PH:3/DP:4/AT:3/CH:4/SR:4/SX:2/OR:3/EV:2/LS:PATCH_AVAILABLE

Exposure EX=1 (execution complexity-bound) · bands PH=HIGH · DP=CRITICAL · AT=HIGH → base CRITICAL · caps low-exposure cap → assessed CRITICAL.

  • RE2 — Wi-Fi radio proximity, unauthenticated, no association or victim physical access (ADJACENT).
  • EC1 — reliable heap-overflow RCE is exploit-dependent, fragile/timing-sensitive (DoS is easy, code exec is hard).
  • AT3 — native code at wireless-driver/kernel level = device compromise / service-level authority, but not a signing/OTA/identity root, so not 4.
  • PH3 — compromise of a head-worn MR display with cameras and live spatial mapping reduces safety margin and can influence what the wearer perceives as real (mid-use); credible injury (PH4) not demonstrated.
  • DP4 — code execution exposes camera/spatial-map/live-sensor world-model state and can affect rendered-environment integrity.
  • perception_feeds_action — true: the headset’s camera/spatial map drives the wearer’s perception of safety-relevant reality and AR rendering.
  • CH4 — boundary_crossing true: driver/kernel compromise crosses radio->device->perception/safety boundaries and is a reusable bridge.
  • SR4 — same Broadcom driver/payload reused across many affected units (shared-component supply-chain reuse).
  • SX2 — per-device proximity required (range-limited per attacker, one nearby unit at a time).
  • OR3 — requires firmware/driver update push to detect/recover; not a full recall or signing-root rotation.
  • EV2 — report-backed advisory, no field exploitation observed.
  • active_exploitation — false.

DEVICE_AVAILABILITYHIGH

CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:2/EC:4/EX:2/PH:3/DP:0/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLE

Exposure EX=2 (reachability-bound) · bands PH=HIGH · DP=MONITOR · AT=ELEVATED → base HIGH → assessed HIGH.

  • DoS branch (CVSS A:H).
  • RE2 — Wi-Fi proximity, unauthenticated, no physical access.
  • EC4 — DoS via crafted frames is trivial/single-request and reliable (explicitly stated as trivial).
  • PH2 — a crash mid-use disrupts the wearer / workflow availability disruption without severe harm.
  • DP0 — pure crash, no data exposure on this path.
  • AT2 — bounded availability impact of the device/component, no authority gain.
  • CH2 — boundary_crossing true: crosses radio->device boundary but is not a reusable cross-domain authority bridge on its own.
  • SR4 — identical frame payload reusable against any affected Broadcom-driver unit (shared component).
  • SX2 — per-device proximity, range-limited per attacker.
  • OR2 — device reboots/recovers; firmware update needed to prevent recurrence but no fleet reprovision.
  • EV2 — report-backed.
  • active_exploitation — false.

Published baseline

  • v3.1 8.3 HIGH — CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H — NVD (CVE-2019-9500)
  • v3.1 7.9 HIGH — CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H — CERT/CC via NVD (CVE-2019-9500)
  • v3.1 8.8 HIGH — CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — NVD (CVE-2019-9501)
  • v3.1 7.9 HIGH — CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H — CERT/CC via NVD (CVE-2019-9501)
  • v3.1 8.8 HIGH — CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — NVD (CVE-2019-9502)
  • v3.1 7.9 HIGH — CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H — CERT/CC via NVD (CVE-2019-9502)
  • v3.1 8.3 HIGH — CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H — NVD (CVE-2019-9503)
  • v3.1 7.9 HIGH — CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H — CERT/CC via NVD (CVE-2019-9503)

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0014 (“HoloLens Broadcom Wi-Fi over-the-air RCE/DoS (ADV190017: CVE-2019-9501/9503)”), paths.cfse.ai/CPATH-2026-0014 (published 2026-06-03).