Qualcomm Products Memory Corruption Vulnerability in HLOS

Vulnerability

A memory corruption vulnerability has been identified in various chipsets of Qualcomm products, including those in the Snapdragon series, automotive platforms, and WLAN firmware. This vulnerability arises from the use of uninitialized variables while processing identity credential operations in the trusted application, which could potentially be exploited to cause memory corruption.

Impact

Exploitation of this vulnerability leads to memory corruption, which can cause unpredictable behavior in the application, including potential information disclosure or allowing for further exploitation of the device.

Remediation

Qualcomm has notified customers about this vulnerability and is actively sharing patches. Instructions for applying the patch can be found in the January 2026 Qualcomm Security Bulletin.

Added: Jan 7, 2026, 1:08 PM
Updated: Jan 7, 2026, 1:08 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
3.5
remediation
7.7
relevance
1.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.