CVE-2025-59607
massMemory Corruption in Qualcomm Component from Oversized Input Copy
CVE-2025-59607 is a memory corruption flaw (untrusted pointer dereference, CWE-822) in a Qualcomm component, triggered when copying input data that exceeds normal allocation limits. A local attacker who already has low privileges on a device can supply oversized input to the affected component with no user interaction required, causing the corruption. The high ratings for confidentiality, integrity, and availability in the CVSS score indicate the flaw can likely lead to privileged code execution or a system-level crash. The advisory was issued by Qualcomm Product Security, but the specific affected chipset, component, and version range are not stated in the available data, so affected devices cannot be precisely enumerated. No public proof-of-concept exists and the flaw is not in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently known to be occurring.
What to do: Monitor Qualcomm security bulletins and your device OEM's Android security patch releases, and apply the firmware/driver fix for the affected component as soon as it is identified. Because the attack vector is local and requires only low privileges, avoid installing untrusted apps or granting local access on Qualcomm-based devices until patched.
| Qualcomm | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory Corruption when copying large input data exceeds normal allocation limits.
- Weakness
- CWE-822
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.