Impact
The vulnerability is a buffer over‑read (CWE‑126) that occurs when memory is allocated with sizes exceeding the maximum allowed value. This can result in memory corruption that affects program data integrity.
Affected Systems
Qualcomm Snapdragon chipsets; any device that incorporates a Snapdragon processor could be impacted unless a vendor patch has been applied, as detailed in Qualcomm’s July 2026 security bulletin. Specific affected firmware versions are not disclosed.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. No specific attack vector is disclosed, so the threat assessment relies on the CVSS metrics alone.
OpenCVE Enrichment