CVE Field Guide
About Us
CVE-2026-25262
PUBLISHED
Write-what-where Condition in Primary Bootloader
Assigner:
qualcomm
Reserved:
02.02.2026
Published:
22.09.2026
Updated:
22.09.2026
Memory corruption while processing a crafted ELF file in the Primary Bootloader.
Metrics
CVSS 3.1
CVSS Vector:
CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS Score:
6.9
CVSS score
6.9
Attack Vector
Physical
Scope
Changed
Attack Complexity
High
Confidentiality Impact
High
Privileges Required
Low
Integrity Impact
High
User Interaction
Required
Availability Impact
High
CVSS 3.1
Product Status
Vendor
Qualcomm, Inc.
Product
Snapdragon
Versions
Default:
unaffected
Version MDM9x07 is affected
Version MDM9x45 is affected
Version MDM9x55 is affected
Version MDM9x65 is affected
Version MSM8909 is affected
Version MSM8916 is affected
Version MSM8952 is affected
Version SDX50 is affected
References
https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2026-bulletin.html
Problem Types
CWE-123: Write-what-where Condition
CWE