Executive brief
A memory corruption vulnerability exists in Qualcomm component processing when handling escape sequences with insufficient user buffer allocation. An attacker can exploit this flaw to cause memory corruption, potentially leading to denial of service or code execution on affected devices.
Technical details
The vulnerability is a memory corruption flaw in the escape handling flow triggered by insufficient user buffer sizes. The attack vector is network or local access depending on the specific Qualcomm component affected. No authentication is typically required to trigger the vulnerability. Successful exploitation can result in memory corruption leading to denial of service, information disclosure, or potentially remote code execution. Qualcomm has published security updates in their September 2026 bulletin addressing this issue.
Affected products
- Qualcomm <UNKNOWN>
Timeline
- 2026-09-17: disclosed