ZeroHour

CVE-2025-59607

mass

Memory Corruption in Qualcomm Component from Oversized Input Copy

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2025-59607 is a memory corruption flaw (untrusted pointer dereference, CWE-822) in a Qualcomm component, triggered when copying input data that exceeds normal allocation limits. A local attacker who already has low privileges on a device can supply oversized input to the affected component with no user interaction required, causing the corruption. The high ratings for confidentiality, integrity, and availability in the CVSS score indicate the flaw can likely lead to privileged code execution or a system-level crash. The advisory was issued by Qualcomm Product Security, but the specific affected chipset, component, and version range are not stated in the available data, so affected devices cannot be precisely enumerated. No public proof-of-concept exists and the flaw is not in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently known to be occurring.

What to do: Monitor Qualcomm security bulletins and your device OEM's Android security patch releases, and apply the firmware/driver fix for the affected component as soon as it is identified. Because the attack vector is local and requires only low privileges, avoid installing untrusted apps or granting local access on Qualcomm-based devices until patched.

Affected
Qualcomm
Estimated exposure
masspotentially hundreds of millions to billions of devices (Qualcomm silicon powers a large share of Android smartphones and IoT), though the specific affected… — Estimated from Qualcomm's dominant share of mobile SoC and embedded deployments (billions of Android and IoT devices in public market-share data), with the caveat that the source data does not name the affected component or versions, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Memory Corruption when copying large input data exceeds normal allocation limits.

Weakness
CWE-822
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.