Impact
A bug in Snapdragon’s OOBM component causes an integer overflow or wraparound when validating large data buffers from external sources. The addition used to check buffer length can exceed the maximum value of the integer type, leading to memory corruption. An attacker could exploit this by sending specially crafted data, potentially allowing escalation of privileges or execution of arbitrary code if the overflow corrupts control flows.
Affected Systems
Qualcomm Snapdragon processors are affected. The specific firmware or kernel versions are not disclosed in the advisory, so any Snapdragon device running the involved OOBM component is potentially vulnerable. Users of Qualcomm hardware should consult the September 2026 security bulletin for version details.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score is below 1 %, suggesting a low likelihood of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog, so no confirmed exploits are reported. If an attacker can supply input to the OOBM component, the overflow may enable remote or local code execution depending on the privilege level of the affected process.
OpenCVE Enrichment