Memory Corruption Vulnerability in Qualcomm Software Products
CVE-2026-25258

7.8HIGH

Key Information:

Vendor

Qualcomm

Vendor
CVE Published:
1 June 2026

What is CVE-2026-25258?

This vulnerability involves memory corruption that occurs during the processing of IOCTL (Input Output Control) calls specifically related to escape operations. An attacker could potentially exploit this flaw to execute arbitrary code, gain elevated privileges, or disrupt system functionality. Proper validation and error handling during IOCTL operations are crucial to mitigate this risk and ensure the integrity of Qualcomm’s software environment.

Affected Version(s)

Snapdragon Snapdragon Compute Cologne

Snapdragon Snapdragon Compute FastConnect 6900

Snapdragon Snapdragon Compute FastConnect 7800

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.