Junglewise Threat Intelligence

CVE-2025-59604: Qualcomm Snapdragon memory corruption via NULL pointer dereference

CVE-2025-59604 · Severity: high · CVSS 7.8 · Published 2026-06-01

Technologies: Qualcomm Snapdragon Mobile. Vendors: Qualcomm.

Executive brief

A memory corruption vulnerability exists in Qualcomm chipset software, which is used to power a wide range of mobile devices and embedded systems. An attacker with local access to a device could exploit this flaw to crash the system or potentially gain unauthorized access to sensitive data. This could lead to a total compromise of the device's security and operational integrity.

Technical details

A NULL pointer dereference (CWE-476) exists in Qualcomm firmware/software during memory copy operations. The vulnerability is triggered when the system attempts to perform an invalid write operation using a null pointer, leading to memory corruption. An attacker with local access and low privileges can exploit this to achieve high impact on confidentiality, integrity, and availability. The issue was disclosed in the June 2026 Qualcomm Security Bulletin. Mitigation typically requires applying firmware updates provided by the device manufacturer.

Affected products

  • Qualcomm Snapdragon Mobile

Timeline

  • 2026-06-01: advisory: Published in Qualcomm June 2026 Security Bulletin
  • 2026-06-01: disclosed

References

Related threats