Junglewise Threat Intelligence

CVE-2026-25258: Qualcomm Snapdragon memory corruption in IOCTL escape operations

CVE-2026-25258 · Severity: high · CVSS 7.8 · Published 2026-06-01

Technologies: Qualcomm Snapdragon Mobile. Vendors: Qualcomm.

Executive brief

A security vulnerability exists in Qualcomm chipsets used in many mobile devices. This flaw occurs when the system processes specific hardware communication requests, potentially allowing a malicious application installed on the device to gain unauthorized access to sensitive data or cause system crashes. This could lead to a total compromise of the device's security and stability.

Technical details

A memory corruption vulnerability exists in Qualcomm firmware/drivers due to improper handling of IOCTL (Input/Output Control) calls during escape operations. The vulnerability is classified as an out-of-bounds read (CWE-125), though the reported impact includes high confidentiality, integrity, and availability loss, suggesting it may lead to broader memory corruption or privilege escalation. An attacker with local access and low privileges can exploit this flaw to read sensitive memory or crash the system. The issue was disclosed in the June 2026 Qualcomm Security Bulletin.

Affected products

  • Qualcomm Snapdragon Mobile

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory: Qualcomm June 2026 Security Bulletin published

References

Related threats