CVE-2026-25290
massInteger Overflow Memory Corruption in Qualcomm Product Buffer Validation
An integer overflow (CWE-190) in a Qualcomm product component corrupts memory when very large data buffers from external sources are validated: because the length check is performed using addition, the computed size can wrap around and incorrectly pass validation. A local, low-privileged attacker (CVSS:3.1 AV:L/AC:L/PR:L/UI:N) could trigger the flaw by supplying a crafted oversized buffer, with high potential impact on confidentiality, integrity, and availability, typically enabling memory corruption that may lead to code execution or a crash in the affected component. The advisory was assigned by Qualcomm's product security team, but the specific affected chipsets, components, and firmware versions are not identified in the available data. Exploitation is not currently known: the issue is absent from CISA's KEV catalog and no public proof-of-concept exists.
What to do: Monitor Qualcomm's security bulletin for the advisory covering CVE-2026-25290 and apply OEM firmware/Android security updates as soon as fixed versions are published, since the specific patched versions are not yet identified in the available data. Because exploitation requires local access with low privileges, prioritize patching devices that run untrusted applications and restrict installation of untrusted local software on Qualcomm-based devices in the interim.
| Qualcomm | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.