Memory Corruption Vulnerability in Qualcomm Products
CVE-2026-25289

9.6CRITICAL

Key Information:

Vendor

Qualcomm

Vendor
CVE Published:
4 August 2026

What is CVE-2026-25289?

A vulnerability in Qualcomm NAN Services can lead to memory corruption due to improper handling of Device Capability Extended attributes in certain NAN Service Discovery Frames. This issue arises when the frames contain invalid length values, which could potentially allow an attacker to exploit the affected system, leading to unpredictable behavior, potential system crashes, or unauthorized access.

Affected Version(s)

Snapdragon Snapdragon Auto AR8035

Snapdragon Snapdragon Auto Cologne

Snapdragon Snapdragon Auto CQ7790

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.