Improper Access Control in Universal Boot Loader Affects Qualcomm Products
CVE-2025-24857

7.6HIGH

Key Information:

Vendor

Qualcomm

Vendor
CVE Published:
10 December 2025

What is CVE-2025-24857?

A vulnerability exists in the Universal Boot Loader that impacts various Qualcomm chipsets. The issue arises from improper access control of volatile memory that contains boot code. This flaw could lead to the execution of arbitrary code if exploited, posing a significant risk to device integrity. Users of affected Qualcomm products should take immediate precautions to mitigate potential attacks.

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.