Qualcomm Products Shared Buffer Access Race Condition Vulnerability Allowing Memory Corruption

Vulnerability

A vulnerability exists in various chipsets used in Qualcomm products, allowing memory corruption by accessing shared buffers without proper validation of concurrent user-mode input changes. This issue arises from a time-of-check time-of-use (TOCTOU) race condition, where the timing of input modification and buffer access can be manipulated, leading to memory corruption.

Impact

Exploitation of this vulnerability causes memory corruption, which can lead to undefined behavior in the application, including potential arbitrary code execution or causing the device to crash.

Remediation

Qualcomm has notified customers about this vulnerability and is actively sharing patches with device manufacturers. Instructions for applying the patch can be found in the Qualcomm June 2026 Security Bulletin.

Added: Jun 1, 2026, 11:54 PM
Updated: Jun 1, 2026, 11:54 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
2.9
remediation
7.7
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.