Junglewise Threat Intelligence

CVE-2026-25260: Qualcomm Snapdragon memory corruption via TOCTOU in shared buffers

CVE-2026-25260 · Severity: high · CVSS 7.8 · Published 2026-06-01

Technologies: Qualcomm Snapdragon Mobile. Vendors: Qualcomm.

Executive brief

A security vulnerability exists in Qualcomm chipsets that could allow a malicious application installed on a device to corrupt system memory. This issue occurs when the system fails to properly manage shared data buffers, potentially allowing an attacker to gain unauthorized access to sensitive information or cause the device to crash. This could lead to a total compromise of the device's data and operational stability.

Technical details

A Time-of-check Time-of-use (TOCTOU) race condition (CWE-367) exists in Qualcomm firmware/drivers. The vulnerability occurs when the system accesses shared buffers without validating concurrent user-mode input modifications, leading to memory corruption. An attacker with local low-privileged access can exploit this race condition to modify buffer contents after validation but before use. Successful exploitation can result in a complete loss of confidentiality, integrity, and availability. Users should refer to the June 2026 Qualcomm Security Bulletin for specific patch information.

Affected products

  • Qualcomm Snapdragon Mobile

Timeline

  • 2026-06-01: advisory: Published by Qualcomm and NVD

References

Related threats