ZeroHour

CVE-2026-25280

mass

Out-of-bounds write in Qualcomm escape handling flow

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-25280 is a memory corruption flaw (CWE-787, out-of-bounds write) in a Qualcomm component, occurring when the escape handling flow processes data into user-supplied buffers whose sizes were not sufficiently validated. It is triggered by a local, low-privileged process that submits data or undersized buffers along this code path, causing memory to be written past the intended bounds. An attacker who already has a foothold on a device (e.g., a malicious app or compromised process) could leverage it for local privilege escalation with high impact on confidentiality, integrity, and availability, per the CVSS 7.8 local-attack vector. Affected parties are users of devices running vulnerable Qualcomm silicon or firmware such as Snapdragon-based smartphones and other Qualcomm-powered products; the specific affected chipsets and version ranges are not enumerated in the available data. The flaw is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so no exploitation is currently confirmed.

What to do: Watch for CVE-2026-25280 in Qualcomm's security bulletin and apply the corresponding OEM/Android monthly security update as soon as your device vendor ships it, since fixes for Qualcomm issues typically arrive via device firmware rather than generic patches. Until patched, limit installation of untrusted apps on affected devices, as the flaw requires local low-privileged access to exploit. Verify the Qualcomm component/firmware version of your devices against the bulletin's affected list once published.

Affected
Qualcomm
Estimated exposure
masspotentially hundreds of millions to billions of devices (Qualcomm silicon powers the majority of Android smartphones, plus IoT and automotive) — Qualcomm's own product security team assigned the CVE, and Qualcomm SoCs/modems ship in the large majority of Android handsets and many embedded products per public market-share trackers, so the plausible upper bound of affected devices is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Memory corruption when processing escape handling flow with insufficient user buffer sizes.

Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.