CVE-2026-25282
massOut-of-Bounds Read in Qualcomm Component Enables Transient Denial of Service
CVE-2026-25282 is an out-of-bounds memory read (CWE-125) in a Qualcomm platform component that occurs when the component processes unverified data originating from a neighboring system. Per the CVSS vector, a local attacker with low privileges and no user interaction required can feed such data to the affected component and trigger the flaw, causing a transient denial of service with high availability impact and low confidentiality/integrity impact. The scope-changed metric suggests the vulnerable code runs in a protected or isolated subsystem, a pattern typical of Qualcomm modem/baseband and similar components. Devices built on affected Qualcomm silicon — which spans a large share of Android smartphones and many IoT and automotive products — are potentially affected, although the specific component, chipset list, and fixed firmware versions are not included in the available data. The issue is not listed in CISA's KEV, and no public proof-of-concept or in-the-wild exploitation is known.
What to do: Check Qualcomm's security bulletin for CVE-2026-25282 to identify the affected chipset(s)/component and the fixing firmware, then apply the corresponding OEM or Android monthly security update as it reaches your devices. Because triggering requires local access to feed unverified data to the affected component, prompt patching and limiting untrusted local applications materially reduce risk. No workaround is documented; monitor vendor advisories for the definitive list of affected parts.
| Qualcomm | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.