CVE-2026-25280
massOut-of-bounds write in Qualcomm escape handling flow
CVE-2026-25280 is a memory corruption flaw (CWE-787, out-of-bounds write) in a Qualcomm component, occurring when the escape handling flow processes data into user-supplied buffers whose sizes were not sufficiently validated. It is triggered by a local, low-privileged process that submits data or undersized buffers along this code path, causing memory to be written past the intended bounds. An attacker who already has a foothold on a device (e.g., a malicious app or compromised process) could leverage it for local privilege escalation with high impact on confidentiality, integrity, and availability, per the CVSS 7.8 local-attack vector. Affected parties are users of devices running vulnerable Qualcomm silicon or firmware such as Snapdragon-based smartphones and other Qualcomm-powered products; the specific affected chipsets and version ranges are not enumerated in the available data. The flaw is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so no exploitation is currently confirmed.
What to do: Watch for CVE-2026-25280 in Qualcomm's security bulletin and apply the corresponding OEM/Android monthly security update as soon as your device vendor ships it, since fixes for Qualcomm issues typically arrive via device firmware rather than generic patches. Until patched, limit installation of untrusted apps on affected devices, as the flaw requires local low-privileged access to exploit. Verify the Qualcomm component/firmware version of your devices against the bulletin's affected list once published.
| Qualcomm | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.