Qualcomm Products Buffer Copy Without Checking Size of Input Vulnerability Allowing Memory Corruption

Vulnerability

A vulnerability exists in various chipsets used in Qualcomm products, including those in mobile platforms, automotive applications, and wireless communication. This vulnerability involves memory corruption caused by improper buffer management during memory operations, particularly when overlapping buffers are copied. The issue arises from incorrect calculations of buffer offsets, leading to potential memory corruption.

Impact

Exploitation of this vulnerability causes memory corruption, which can lead to arbitrary code execution or application crashes, depending on the context in which the vulnerability is exploited.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the January 2026 Qualcomm Security Bulletin.

Added: Jan 7, 2026, 7:47 PM
Updated: Jan 7, 2026, 7:47 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
3.3
remediation
7.7
relevance
1.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.