Junglewise Threat Intelligence

CVE-2026-25268: Qualcomm Snapdragon memory corruption in HT40 channel switching

CVE-2026-25268 · Severity: high · CVSS 8.8 · Published 2026-07-06

Technologies: Qualcomm Snapdragon Compute, Qualcomm Snapdragon, Qualcomm Snapdragon Mobile, Qualcomm Snapdragon Auto. Vendors: Qualcomm.

Executive brief

A security vulnerability exists in various Qualcomm Snapdragon chipsets used in mobile devices, automotive systems, and networking hardware. The flaw occurs when the device handles specific Wi-Fi channel switching operations, which could allow a malicious actor with local access to corrupt the system's memory. If exploited, this could lead to a complete system takeover, unauthorized data access, or permanent device instability.

Technical details

A stack-based buffer overflow (CWE-121) exists in Qualcomm Snapdragon firmware during the processing of HT40 (High Throughput 40MHz) channel layouts. The vulnerability is triggered during dynamic channel switching operations when the system encounters an invalid layout configuration. An attacker with local low-privileged access can exploit this to cause memory corruption. Given the 'Changed' scope (S:C) in the CVSS vector, this vulnerability may allow an attacker to escape a restricted environment or impact the underlying secure processor/hypervisor, potentially leading to full system compromise (Confidentiality, Integrity, and Availability). Patch information is typically available through the July 2026 Qualcomm Security Bulletin.

Affected products

  • Qualcomm Snapdragon Multiple platforms including Snapdragon Auto, Compute, Mobile, and FastConnect (see advisory for full list)

Timeline

  • 2026-07-06: advisory: Published by Qualcomm and NVD

References

Related threats