Junglewise Threat Intelligence

CVE-2026-25277: Qualcomm Strongbox buffer overflow memory corruption

CVE-2026-25277 · Severity: high · CVSS 8.8 · Published 2026-06-01

Vendors: Qualcomm.

Executive brief

A security vulnerability exists in Qualcomm's Strongbox, a hardware-backed security component used to protect sensitive cryptographic keys and data on mobile devices. An attacker with local access to the device could exploit this flaw to corrupt system memory, potentially leading to the theft of secure information or a complete system takeover. This poses a significant risk to the integrity of the device's most sensitive security operations.

Technical details

A classic buffer overflow (CWE-120) exists in the Qualcomm Strongbox component. The vulnerability is triggered when the system performs a buffer copy without properly checking the size of the input, leading to memory corruption. An attacker with local access and low privileges can exploit this flaw to achieve a scope cross (S:C), potentially gaining unauthorized access to the secure execution environment. This can result in a total loss of confidentiality, integrity, and availability for the affected component. The issue was disclosed in the June 2026 Qualcomm security bulletin.

Affected products

  • Qualcomm Strongbox

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory

References