Executive brief
A memory corruption vulnerability exists in Qualcomm chipset software when processing specific hardware control commands. An attacker with local access to a device could exploit this flaw to gain unauthorized access to sensitive data or cause the system to crash. This affects the underlying hardware communication layer used in many mobile devices and automotive systems.
Technical details
A memory corruption vulnerability, specifically an out-of-bounds write (CWE-787), exists in Qualcomm chipset firmware/drivers. The issue occurs during the processing of multiple Input/Output Control (IOCTL) commands for 'escape' operations. A local attacker with low privileges can trigger this flaw by sending crafted IOCTL requests to the driver. Successful exploitation can lead to arbitrary code execution with elevated privileges, data confidentiality breaches, or a complete system denial of service. The vulnerability was addressed in the Qualcomm June 2026 security bulletin.
Affected products
- Qualcomm Snapdragon Mobile
Timeline
- 2026-06-01: advisory: Qualcomm published the June 2026 security bulletin.
- 2026-06-01: disclosed: CVE-2026-25259 was published to the NVD.