Executive brief
A flaw in Qualcomm's NG-eCall (Next Generation emergency call) system can expose sensitive SIP signaling data when IPSec negotiation fails or is not properly established. This affects emergency call services, potentially exposing caller identity, location, or other sensitive communication metadata to network eavesdropping.
Technical details
This is an information disclosure vulnerability in the NG-eCall SIP signaling protocol implementation. The root cause is improper handling of IPSec negotiation failures, resulting in SIP messages and related sensitive data being transmitted without proper encryption protection when IPSec is not established. An attacker with network access can passively intercept unencrypted SIP traffic to obtain caller information, call metadata, and other confidential details. No authentication or user interaction is required for exploitation; the vulnerability occurs automatically during failed or incomplete IPSec setup.
Affected products
- Qualcomm NG-eCall
Timeline
- 2026-08-04: disclosed