ZeroHour

CVE-2026-25282

mass

Out-of-Bounds Read in Qualcomm Component Enables Transient Denial of Service

CVSS 3.1
7.9 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-25282 is an out-of-bounds memory read (CWE-125) in a Qualcomm platform component that occurs when the component processes unverified data originating from a neighboring system. Per the CVSS vector, a local attacker with low privileges and no user interaction required can feed such data to the affected component and trigger the flaw, causing a transient denial of service with high availability impact and low confidentiality/integrity impact. The scope-changed metric suggests the vulnerable code runs in a protected or isolated subsystem, a pattern typical of Qualcomm modem/baseband and similar components. Devices built on affected Qualcomm silicon — which spans a large share of Android smartphones and many IoT and automotive products — are potentially affected, although the specific component, chipset list, and fixed firmware versions are not included in the available data. The issue is not listed in CISA's KEV, and no public proof-of-concept or in-the-wild exploitation is known.

What to do: Check Qualcomm's security bulletin for CVE-2026-25282 to identify the affected chipset(s)/component and the fixing firmware, then apply the corresponding OEM or Android monthly security update as it reaches your devices. Because triggering requires local access to feed unverified data to the affected component, prompt patching and limiting untrusted local applications materially reduce risk. No workaround is documented; monitor vendor advisories for the definitive list of affected parts.

Affected
Qualcomm
Estimated exposure
masspotentially hundreds of millions of devices (exact count unknown pending component/chipset disclosure) — Qualcomm is the dominant supplier of Android SoCs and modems with billions of deployed devices, so a flaw in one of its platform components plausibly touches hundreds of millions of devices, but the available data does not name the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

In the news

No ingested article mentions this CVE yet.