Skip to content
QualcommCVE-2026-25254

Qualcomm Snapdragon: improper authorization

Critical9.8CVE-2026-25254 · Published Sep 22, 2026 · updated Sep 25, 2026

Improper authorization leads to Remote Code Execution via SocketIO interface.

Qualcomm advisory

Affected versions

PackageAffectedFixed in
Snapdragon
Product
<= QSCv1.17.1No fix yet
<= QSCv1.19.1No fix yet
<= QSCv1.21.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-285

More Qualcomm advisories

All Qualcomm
Advisory
Qualcomm Snapdragon: privilege escalation
High8.8Sep 22
Qualcomm Snapdragon: privilege escalation
High8.8Sep 22
Qualcomm Snapdragon: privilege escalation
High8.8Sep 22
Qualcomm Snapdragon: memory corruption
Medium6.9Sep 22
Qualcomm Snapdragon: resource exhaustion
High7.4Sep 17
Qualcomm Snapdragon: out-of-bounds read
High7.9Sep 17

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.