Qualcomm Modem Improper Input Validation Vulnerability Leading to Transient Denial-of-Service

Vulnerability

A vulnerability has been identified in the modem component of various chipsets, including those in the Snapdragon 8 Gen 1 and 8 Gen 2 mobile platforms, as well as several other Snapdragon and Qualcomm platforms. This vulnerability arises from improper input validation when processing CCCH data. The issue occurs remotely when the network sends data with invalid length, leading to a transient denial-of-service condition.

Impact

Exploitation of this vulnerability causes a transient denial-of-service condition by disrupting the normal processing of CCCH data, potentially leading to temporary unavailability of services dependent on this data.

Remediation

Qualcomm has notified customers about this vulnerability and is actively sharing patches. Instructions for applying the patch can be found in the Qualcomm August 2025 Security Bulletin.

Added: Aug 6, 2025, 10:23 AM
Updated: Aug 6, 2025, 10:23 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
5.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.