Qualcomm Products Display TOCTOU Race Condition Vulnerability Allowing Memory Corruption

Vulnerability

A time-of-check time-of-use (TOCTOU) race condition vulnerability has been identified in various chipsets of Qualcomm products, specifically within the display technology area. This vulnerability allows memory corruption by processing simultaneous requests through an escape path, potentially leading to unauthorized access or manipulation of memory.

Impact

Exploitation of this vulnerability causes memory corruption, which can lead to arbitrary code execution or other unintended behavior by manipulating the application's memory.

Remediation

Qualcomm has notified customers about this vulnerability and shared patch instructions. The patch can be applied by following the instructions available in the Qualcomm August 2025 Security Bulletin.

Added: Aug 6, 2025, 8:26 AM
Updated: Aug 6, 2025, 8:26 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
2.9
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.