Critical 9.8 CVSS Flaws in Qualcomm Chipsets Enable Remote Takeover
ID: 8892b9a8-3bac-5f82-b88b-07c33b3c2ebf
STIX ID: report--8892b9a8-3bac-5f82-b88b-07c33b3c2ebf
Feed Name: securityonline.info
Qualcomm's May 2026 security bulletin discloses multiple high-severity vulnerabilities—notably CVE-2026-25254 (SocketIO improper authorization leading to remote code execution, CVSS 9.8), CVE-2026-25293 (PLC firmware authorization flaw causing a buffer overflow, CVSS 9.6), and CVE-2026-25262 (primary bootloader write-what-where via crafted ELF causing memory corruption)—affecting a broad set of Qualcomm chipsets and requiring OEM-distributed patches; remote RCEs risk large-scale compromise of smartphones and IoT devices while the bootloader flaw threatens boot integrity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
