Qualcomm HLOS Out-of-bounds Write Vulnerability Allowing Memory Corruption

Vulnerability

A memory corruption vulnerability has been identified in Qualcomm's HLOS (High-Level Operating System) component. This issue arises from an out-of-bounds write when processing device identifier strings that exceed the expected maximum length. The vulnerability affects several chipsets, including those used in various Snapdragon mobile platforms and other Qualcomm technologies.

Impact

Exploitation of this vulnerability leads to memory corruption, which can potentially be exploited to execute arbitrary code or cause a denial-of-service condition.

Remediation

Qualcomm has notified customers about this vulnerability and is actively sharing patches with OEMs. Instructions for applying the patch can be found in the Qualcomm June 2026 Security Bulletin.

Added: Jun 1, 2026, 11:46 PM
Updated: Jun 1, 2026, 11:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.7
remediation
8.3
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.