ZeroHour

CVE-2026-25284

mass

Use-After-Free Information Disclosure in Qualcomm Component

CVSS 3.1
7.3 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-25284 is an information disclosure flaw caused by a use-after-free condition: a pointer to freed memory is reused, and the resulting out-of-bounds read (CWE-126, buffer over-read) returns memory contents to the caller. A local attacker who already holds low privileges on the device can trigger the dangling-pointer reuse without any user interaction, and the CVSS scope change (S:C) indicates the leaked data crosses a security boundary, potentially exposing memory belonging to a more privileged component. The attacker gains read access to sensitive memory contents (high confidentiality impact) but cannot modify data and causes only minor availability impact. Affected devices are those running the impacted Qualcomm software or firmware; the specific chipset or component name and the version ranges were not included in the source data. The flaw is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation has not been confirmed.

What to do: Watch the Qualcomm security bulletin for CVE-2026-25284 and apply firmware/OS updates from your device or OEM vendor as they roll out, since Qualcomm typically ships fixes through OEM builds. Because exploitation requires local access with low privileges, limit untrusted apps and local accounts on potentially affected devices. Inventory which products run Qualcomm components and verify whether your specific chipset or firmware version is named in the advisory once published.

Affected
Qualcomm component (specific product not identified in source data)
Estimated exposure
masslikely millions of devices (Qualcomm silicon ships in 1B+ consumer and embedded devices; affected subset unknown) — Qualcomm chipsets and software components are deployed in well over a billion smartphones and embedded devices worldwide, but because the affected component and version range are not disclosed, the exact affected population cannot be…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Information Disclosure when a pointer is reused after being deallocated.

Weakness
CWE-126
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.