Qualcomm Products Buffer Copy Without Checking Size of Input Vulnerability in Computer Vision

Vulnerability

A memory corruption vulnerability has been identified in various chipsets of Qualcomm products, including those in the Snapdragon 8 and 7 series, as well as in several platforms such as Windows WLAN Host and core services. This vulnerability arises from improper validation of packet data, particularly when processing exceedingly large packets, which can lead to classic buffer overflow scenarios. The issue can be exploited locally, causing memory corruption that could potentially be leveraged for arbitrary code execution.

Impact

Exploitation of this vulnerability leads to memory corruption, creating a classic buffer overflow scenario. Such memory corruption can often be exploited to execute arbitrary code, particularly in environments where the affected application has elevated privileges.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm July 2025 Security Bulletin.

Added: Jul 8, 2025, 1:27 PM
Updated: Jul 8, 2025, 1:27 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.