Qualcomm Snapdragon Chipsets Mailbox Read API Information Disclosure Vulnerability

Vulnerability

A buffer over-read vulnerability has been identified in various chipsets of Qualcomm Snapdragon products, specifically within the Automotive Autonomy technology area. This vulnerability allows information disclosure while invoking the mailbox read API, potentially leading to unauthorized access to sensitive data.

Impact

Exploitation of this vulnerability can result in information disclosure, allowing unauthorized access to data that may be sensitive or confidential.

Remediation

Qualcomm has notified customers about this vulnerability and is actively sharing patches with device manufacturers. Instructions for applying the patch can be found in the Qualcomm January 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
3.5
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.