Junglewise Threat Intelligence

CVE-2025-59613: Qualcomm Snapdragon stack-based buffer overflow in data copying

CVE-2025-59613 · Severity: medium · CVSS 6.7 · Published 2026-06-01

Technologies: Qualcomm Snapdragon Mobile. Vendors: Qualcomm.

Executive brief

A memory corruption vulnerability exists in Qualcomm chipset software during data copying operations. This flaw occurs when the system fails to properly validate that the destination storage area is large enough for the incoming data. If exploited, a high-privileged attacker could potentially crash the system or gain unauthorized access to sensitive information, impacting the overall stability and security of the mobile device.

Technical details

A stack-based buffer overflow (CWE-121) exists in Qualcomm firmware due to improper bounds checking during data copy operations. The vulnerability is triggered when an output buffer is smaller than the input buffer, leading to memory corruption. An attacker with high privileges (PR:H) can exploit this locally to achieve arbitrary code execution, data exfiltration, or a denial-of-service condition. The issue was disclosed in the June 2026 Qualcomm security bulletin.

Affected products

  • Qualcomm Snapdragon Mobile

Timeline

  • 2026-06-01: advisory: Initial disclosure by Qualcomm and NVD publication.

References

Related threats