Junglewise Threat Intelligence

CVE-2025-59615: Qualcomm Snapdragon memory corruption in persistent memory IOCTL

CVE-2025-59615 · Severity: medium · CVSS 6.6 · Published 2026-07-06

Technologies: Qualcomm Fastconnect 6700, Qualcomm Snapdragon Compute, Qualcomm Snapdragon Mobile, Qualcomm Fastconnect 6900, Qualcomm Snapdragon 8 Elite Gen 5, Qualcomm Snapdragon Consumer IOT, Qualcomm Qcm6490, Qualcomm Qcm5430, Qualcomm Fastconnect 7800, Qualcomm Sc8380xp. Vendors: Qualcomm.

Executive brief

A memory corruption vulnerability exists in various Qualcomm Snapdragon chipsets used in mobile devices, laptops, and IoT hardware. An attacker with local access to a device could exploit this flaw to disrupt system operations or potentially gain unauthorized control over sensitive memory areas. This could lead to device instability or the compromise of protected user data.

Technical details

A Use-After-Free (CWE-416) vulnerability exists in Qualcomm Snapdragon firmware due to improper synchronization during device input/output control (IOCTL) operations. Specifically, the flaw occurs when mapping and unmapping persistent memory buffers. A local attacker with low privileges can trigger this race condition, leading to memory corruption. Successful exploitation could allow an attacker to achieve arbitrary code execution or escalate privileges, though the attack requires specific timing and user interaction. Patches are typically distributed via OEM security updates.

Affected products

  • Qualcomm Snapdragon CCW
  • Qualcomm Snapdragon Compute
  • Qualcomm Snapdragon Consumer IOT
  • Qualcomm Snapdragon MC
  • Qualcomm Snapdragon Mobile
  • Qualcomm FastConnect 6700
  • Qualcomm FastConnect 6900
  • Qualcomm FastConnect 7800
  • Qualcomm QCM5430
  • Qualcomm QCM6490
  • Qualcomm SC8380XP
  • Qualcomm SD865 5G
  • Qualcomm Snapdragon 8 Elite Gen 5

Timeline

  • 2026-07-06: advisory: Published in Qualcomm July 2026 Security Bulletin

References