Memory Corruption in Primary Bootloader Affecting Qualcomm Products
CVE-2026-25262

6.9MEDIUM

Key Information:

Vendor

Qualcomm

Vendor
CVE Published:
22 September 2026

What is CVE-2026-25262?

A memory corruption vulnerability exists within the Primary Bootloader when processing a specifically crafted ELF file. This flaw can lead to potential unauthorized access or execution of malicious code, posing significant security risks to devices utilizing affected Qualcomm Snapdragon processors. Users are urged to apply necessary mitigations and updates to protect against exploitation.

Affected Version(s)

Snapdragon Snapdragon Auto MDM9x07

Snapdragon Snapdragon Auto MDM9x45

Snapdragon Snapdragon Auto MDM9x55

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.