Junglewise Threat Intelligence

CVE-2025-59610: Qualcomm Chipset memory corruption in IOCTL processing

CVE-2025-59610 · Severity: medium · CVSS 6.4 · Published 2026-06-01

Technologies: Qualcomm Snapdragon Mobile. Vendors: Qualcomm.

Executive brief

A memory corruption vulnerability exists in Qualcomm chipset software when handling specific input/output control requests. An attacker with high-level system privileges could exploit this flaw to cause a system crash or potentially gain unauthorized access to sensitive data. This issue primarily impacts mobile devices and hardware utilizing affected Qualcomm components.

Technical details

A Time-of-Check Time-of-Use (TOCTOU) race condition (CWE-367) exists in Qualcomm chipset firmware during the processing of IOCTL requests. The vulnerability is triggered when there is a mismatch in API versions and a concurrent modification of the user-space buffer occurs during processing. A local attacker with high privileges can exploit this race condition to cause memory corruption. This can lead to a complete compromise of confidentiality, integrity, and availability (C/I/A) on the affected system. The attack complexity is high due to the precise timing required to modify the buffer between the check and use phases.

Affected products

  • Qualcomm Snapdragon Mobile

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory

References

Related threats