Junglewise Threat Intelligence

CVE-2026-25284: Qualcomm component use-after-free information disclosure

CVE-2026-25284 · Severity: high · CVSS 7.3 · Published 2026-09-17

Executive brief

A memory safety vulnerability in Qualcomm components allows a pointer to be reused after being freed, potentially exposing sensitive information. An attacker with local access could exploit this flaw to read memory containing confidential data, such as encryption keys or personal information stored in RAM.

Technical details

This is a use-after-free vulnerability where a pointer is reused after the memory it references has been deallocated. The flaw allows an attacker to read freed memory, leading to information disclosure. The vulnerability requires local access to the affected system. Successful exploitation could reveal sensitive data that remains in memory after deallocation. A patch from Qualcomm is available as of the September 2026 security bulletin.

Affected products

  • Qualcomm <UNKNOWN>

Timeline

  • 2026-09-17: disclosed
  • 2026-09: patched: Patch included in September 2026 security bulletin

References

Related threats