Junglewise Threat Intelligence

CVE-2025-59614: Qualcomm Snapdragon memory corruption in random number generator

CVE-2025-59614 · Severity: medium · CVSS 6.7 · Published 2026-06-01

Technologies: Qualcomm Snapdragon Mobile. Vendors: Qualcomm.

Executive brief

A memory corruption vulnerability exists in certain Qualcomm chipsets when processing random number generator commands. An attacker with high-level system privileges could exploit this flaw to cause a system crash or potentially execute unauthorized code. This could lead to a total loss of device confidentiality, integrity, and availability, impacting the overall security of the mobile device.

Technical details

A memory corruption vulnerability, classified as an out-of-bounds write (CWE-787), exists in Qualcomm firmware. The issue occurs when the system processes a random number generator (RNG) command but the provided output buffer is too small to contain the generated data. An attacker with administrative or high-level local privileges (PR:H) can trigger this condition to overwrite adjacent memory. This can result in a denial-of-service (system crash) or potentially arbitrary code execution within a privileged context. The vulnerability was disclosed in Qualcomm's June 2026 security bulletin.

Affected products

  • Qualcomm Snapdragon Mobile

Timeline

  • 2026-06-01: advisory: Published by Qualcomm and NVD

References

Related threats