Executive brief
A security vulnerability exists in certain Qualcomm chipsets used in mobile devices when processing Wi-Fi advertisement signals. An attacker could potentially gain access to sensitive information from the device's memory by sending specially crafted Wi-Fi frames. This could lead to a breach of privacy or help an attacker bypass other security protections on the smartphone or tablet.
Technical details
A buffer over-read vulnerability (CWE-126) exists in Qualcomm firmware during the processing of Wi-Fi advertisement frames. The issue is triggered by malformed Multiple BSSID (MBSSID) elements that have an insufficient length field, leading the system to read beyond the intended buffer boundaries. An attacker with low privileges can exploit this over the network, though it requires high complexity and user interaction (as indicated by the CVSS vector). Successful exploitation results in information disclosure, potentially leaking sensitive data from the heap or stack to the attacker. Qualcomm has addressed this in their June 2026 security bulletin.
Affected products
- Qualcomm Snapdragon Mobile
Timeline
- 2026-06-01: advisory: Qualcomm published the security bulletin and CVE details.
- 2026-06-01: disclosed