ZeroHour

CVE-2026-25283

mass

Local Memory Corruption (Buffer Overflow) in Qualcomm Components

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-25283 is a memory-corruption flaw (CWE-121, stack-based buffer overflow) in which copying unverified data from an external source into an allocated buffer exceeds the buffer's size. The CVSS vector (AV:L/AC:L/PR:L/UI:N/S:C) indicates it is triggered by a local attacker with low privileges, such as a malicious app or local process supplying oversized external data to the affected component, with no user interaction required, and that the corruption crosses a security boundary into a more privileged context. A successful attacker gains high confidentiality, integrity, and availability impact in that escaped scope, consistent with privileged code execution, data disclosure, or a crash of the affected subsystem. The CVE was assigned by Qualcomm's product security team, so affected products are Qualcomm chipset/firmware components deployed across Android smartphones and other connected hardware, but the provided data does not name the specific component or version range. No exploitation is currently known: the flaw is not on CISA's KEV list and no public proof-of-concept exists.

What to do: Monitor Qualcomm's security bulletin for CVE-2026-25283 and apply the corresponding firmware/driver fix as it is distributed through your device or OEM's security updates. Until patched, reduce risk by restricting untrusted app installs on potentially affected Qualcomm-based devices, since exploitation requires local low-privileged code execution. Once the advisory is published, verify your device model and chipset against Qualcomm's list to confirm whether your hardware is in scope.

Affected
Qualcomm
Estimated exposure
masslikely hundreds of millions of devices (Qualcomm silicon is embedded in a large share of Android phones, automotive, and IoT hardware) — Estimate is based on Qualcomm's chipset footprint in Android devices and connected products, where even a subset of affected chipsets would exceed a million devices; the local (AV:L) attack vector limits exploitability to devices where an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

Weakness
CWE-121
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.