logo

Critical 9.8 CVSS Flaws in Qualcomm Chipsets Enable Remote Takeover

ID: 8892b9a8-3bac-5f82-b88b-07c33b3c2ebf

STIX ID: report--8892b9a8-3bac-5f82-b88b-07c33b3c2ebf

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Ddos

...
...

Qualcomm's May 2026 security bulletin discloses multiple high-severity vulnerabilities—notably CVE-2026-25254 (SocketIO improper authorization leading to remote code execution, CVSS 9.8), CVE-2026-25293 (PLC firmware authorization flaw causing a buffer overflow, CVSS 9.6), and CVE-2026-25262 (primary bootloader write-what-where via crafted ELF causing memory corruption)—affecting a broad set of Qualcomm chipsets and requiring OEM-distributed patches; remote RCEs risk large-scale compromise of smartphones and IoT devices while the bootloader flaw threatens boot integrity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.