Executive brief
A memory corruption vulnerability in Qualcomm firmware allows attackers to exceed buffer limits during data copy operations by supplying large offset and length values. This can lead to memory access violations, potentially enabling code execution, denial of service, or information disclosure on affected devices.
Technical details
The vulnerability is a memory corruption flaw triggered during data copy operations when large offset and length values are processed without proper boundary validation. The root cause is insufficient bounds checking in the firmware's data handling routines, allowing an attacker to write beyond allocated buffer boundaries. Attack vector and preconditions depend on the affected component's exposure; if reachable over the network or via a local interface, exploitation could be possible with varying privilege levels. Successful exploitation can result in arbitrary code execution, denial of service, or information disclosure. Patches are available via Qualcomm's September 2026 security bulletin.
Affected products
- Qualcomm Firmware <UNKNOWN>
Timeline
- 2026-09-17: disclosed