Junglewise Threat Intelligence

CVE-2026-25262: Qualcomm Primary Bootloader memory corruption in ELF processing

CVE-2026-25262 · Severity: medium · CVSS 6.9 · Published 2026-09-22

Vendors: Qualcomm.

Executive brief

Qualcomm's Primary Bootloader contains a memory corruption vulnerability triggered by processing malformed ELF files. An attacker who can supply a crafted ELF file during boot could exploit this flaw to corrupt memory, potentially leading to code execution or denial of service on affected devices. This affects the firmware-level boot process that initializes all Qualcomm-based devices.

Technical details

The vulnerability exists in the ELF file parsing logic of the Primary Bootloader, where insufficient validation of crafted ELF headers or sections can trigger memory corruption. An attacker with access to modify boot-time artifacts or through an adjacent network attack vector during device initialization could supply the malicious ELF file. Successful exploitation may result in arbitrary code execution in the bootloader context or device denial of service.

Affected products

  • Qualcomm Primary Bootloader

Timeline

  • 2026-09-22: disclosed

References