Qualcomm Camera Buffer Over-read Vulnerability Allowing Memory Corruption

Vulnerability

A buffer over-read vulnerability has been identified in Qualcomm's camera component, affecting various chipsets. This vulnerability arises from processing auxiliary sensor input/output control commands without proper validation of buffer sizes, leading to memory corruption. The issue is present in several chipsets across different Qualcomm platforms, including mobile and automotive applications.

Impact

Exploitation of this vulnerability causes memory corruption, which can lead to arbitrary code execution or local privilege escalation, depending on the context.

Remediation

Qualcomm has notified device manufacturers about this vulnerability and recommended that they deploy patches. Instructions for applying the patch can be found in the Qualcomm April 2026 Security Bulletin.

Added: Apr 6, 2026, 4:54 PM
Updated: Apr 6, 2026, 4:54 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
1.3
exploitability
3.3
remediation
7.7
relevance
5.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.