CVE-2026-25283
massLocal Memory Corruption (Buffer Overflow) in Qualcomm Components
CVE-2026-25283 is a memory-corruption flaw (CWE-121, stack-based buffer overflow) in which copying unverified data from an external source into an allocated buffer exceeds the buffer's size. The CVSS vector (AV:L/AC:L/PR:L/UI:N/S:C) indicates it is triggered by a local attacker with low privileges, such as a malicious app or local process supplying oversized external data to the affected component, with no user interaction required, and that the corruption crosses a security boundary into a more privileged context. A successful attacker gains high confidentiality, integrity, and availability impact in that escaped scope, consistent with privileged code execution, data disclosure, or a crash of the affected subsystem. The CVE was assigned by Qualcomm's product security team, so affected products are Qualcomm chipset/firmware components deployed across Android smartphones and other connected hardware, but the provided data does not name the specific component or version range. No exploitation is currently known: the flaw is not on CISA's KEV list and no public proof-of-concept exists.
What to do: Monitor Qualcomm's security bulletin for CVE-2026-25283 and apply the corresponding firmware/driver fix as it is distributed through your device or OEM's security updates. Until patched, reduce risk by restricting untrusted app installs on potentially affected Qualcomm-based devices, since exploitation requires local low-privileged code execution. Once the advisory is published, verify your device model and chipset against Qualcomm's list to confirm whether your hardware is in scope.
| Qualcomm | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.