Description
Memory Corruption when processing device identifier strings that exceed the expected maximum length.
Published: 2026-06-01
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from a memory corruption flaw in the High‑Level Operating System (HLOS) that processes device identifier strings exceeding the expected maximum length, leading to an out‑of‑bounds write (CWE‑787). This flaw can corrupt adjacent memory and potentially allow an attacker to execute arbitrary code, alter system state, or crash the HLOS, causing loss of confidentiality, integrity, and availability.

Affected Systems

Qualcomm Snapdragon devices that run the HLOS are affected, as the issue is tied to the handling of device identifiers within the Qualcomm, Inc. Snapdragon ecosystem. No specific firmware or OS versions are enumerated, so all current Snapdragon HLOS deployments should be evaluated.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity weakness, and while the EPSS score is not available, the lack of a KEV listing suggests moderate exploit prevalence today. Based on the description, the likely attack vector involves supplying crafted device identifier strings, which could be delivered via OTA updates, network communication, or local configuration. An attacker with the ability to influence these inputs could trigger the out‑of‑bounds write during initialization or runtime, enabling remote code execution or denial of service.

Generated by OpenCVE AI on June 1, 2026 at 23:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Qualcomm Snapdragon firmware update that addresses the out‑of‑bounds write.
  • Implement input validation or enforce length limits on device identifier strings before they are processed by the HLOS.
  • Restrict exposure of HLOS interfaces that accept external identifiers by applying network segmentation or firewall rules to limit the attack surface.

Generated by OpenCVE AI on June 1, 2026 at 23:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 01 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when processing device identifier strings that exceed the expected maximum length.
Title Out-of-bounds Write in HLOS
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Qualcomm Snapdragon
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-06-01T22:05:25.625Z

Reserved: 2025-09-18T03:19:23.201Z

Link: CVE-2025-59605

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-01T23:16:15.807

Modified: 2026-06-01T23:16:15.807

Link: CVE-2025-59605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T05:15:06Z

Weaknesses