Executive brief
Qualcomm wireless chipsets used in mobile devices contain a memory corruption vulnerability when processing malformed NAN (Neighbor Awareness Networking) Service Discovery frames with invalid attribute lengths. An attacker with network proximity could exploit this flaw to crash the device or potentially execute arbitrary code, affecting availability and device security.
Technical details
CVE-2026-25289 is a memory corruption vulnerability in Qualcomm wireless chipset firmware handling of NAN (Neighbor Awareness Networking) Service Discovery frames. The vulnerability exists in the Device Capability Extended attribute parser, which fails to properly validate length values before processing frame data, leading to out-of-bounds memory access. An attacker in network or adjacent proximity can send specially crafted NAN Service Discovery frames to trigger the memory corruption. Successful exploitation could result in denial of service (device crash) or remote code execution. A patch from Qualcomm is expected; refer to the August 2026 security bulletin for device-specific fixes.
Affected products
- Qualcomm Wireless Chipset <UNKNOWN>
Timeline
- 2026-08-04: disclosed