Junglewise Threat Intelligence

CVE-2026-25271: Qualcomm Snapdragon memory corruption via TOCTOU race condition

CVE-2026-25271 · Severity: high · CVSS 7.8 · Published 2026-07-06

Technologies: Qualcomm Snapdragon, Qualcomm Wsa8845, Qualcomm Wcd9380, Qualcomm Fastconnect 6900, Qualcomm Wcd9378c, Qualcomm Wsa8840, Qualcomm Wcd9385, Qualcomm Wsa8845h, Qualcomm Fastconnect 7800, Qualcomm Sc8380xp. Vendors: Qualcomm.

Executive brief

A security vulnerability exists in several Qualcomm Snapdragon chipsets used in mobile, industrial, and computing devices. An attacker with local access to a device could exploit a timing issue during data processing to corrupt system memory. This could lead to a complete system crash or allow the attacker to gain unauthorized control over the device's functions and data.

Technical details

This vulnerability is a Time-of-Check Time-of-Use (TOCTOU) race condition (CWE-367) occurring within the firmware of various Qualcomm Snapdragon chipsets. The flaw exists in the handling of asynchronous input parameters where values are modified between the initial validation check and their subsequent use. A local attacker with low privileges can exploit this race condition to trigger memory corruption. Successful exploitation can lead to a loss of confidentiality, integrity, and availability, potentially allowing for arbitrary code execution at a high privilege level. The issue affects multiple platforms including Snapdragon Compute and Industrial IOT.

Affected products

  • Qualcomm Snapdragon Cologne, FastConnect 6900, FastConnect 7800, IQX5121, IQX7181, QCA0000, SC8380XP, WCD9378C, WCD9380, WCD9385, WSA8840, WSA8845, WSA8845H, X2000077, X2000086, X2000090, X2000092, X2000094, XG101002, XG101032, XG101039

Timeline

  • 2026-07-06: disclosed
  • 2026-07-06: advisory: Qualcomm July 2026 Security Bulletin published

References

Related threats