Qualcomm Products Buffer Over-read Vulnerability in Data Network Stack & Connectivity

Vulnerability

A buffer over-read vulnerability has been identified in various chipsets of Qualcomm products, which may lead to information disclosure during video calls. The issue arises when a device resets in response to a non-conforming RTCP packet that does not adhere to RFC standards. This vulnerability affects several chipsets across different Qualcomm platforms, including Snapdragon mobile platforms, automotive platforms, and more.

Impact

Exploitation of this vulnerability can cause a buffer over-read, leading to memory corruption. In the context of a video call, this could result in a device reset, disrupting the call.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm April 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
7.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.