Junglewise Threat Intelligence

CVE-2026-25264: Qualcomm component privilege escalation in package extraction

CVE-2026-25264 · Severity: high · CVSS 8.8 · Published 2026-09-22

Technologies: Microsoft Windows. Vendors: Microsoft, Qualcomm.

Executive brief

A Qualcomm component used during software package extraction contains a weak configuration that allows privilege escalation. An attacker who can influence the package extraction process could gain elevated system privileges, potentially leading to complete device compromise or unauthorized access to sensitive functions.

Technical details

The vulnerability exists in the package extraction process due to improper configuration handling. An attacker with local access or the ability to supply a malicious package can exploit insufficient permission checks during extraction to elevate privileges. A fix is available from Qualcomm via their June 2026 security bulletin.

Affected products

  • Qualcomm Component (package extraction)

Timeline

  • 2026-09-22: disclosed

References

Related threats