CVE-2026-25267: high-severity vulnerability in Qualcomm, Inc. Snapdragon
Missing Authorization in Core
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Qualcomm, Inc. · SnapdragonRelated CVEs — Qualcomm, Inc. Snapdragon
In the same product, most dangerous first.
CVE-2026-21385HIGHInteger Overflow or Wraparound in GraphicsEPSS 1.3%KEVCVE-2025-27038HIGHUse After Free in GraphicsEPSS 1.0%KEVCVE-2025-21479HIGHIncorrect Authorization in GraphicsEPSS 0.8%KEVCVE-2023-33106HIGHUse of Out-of-range Pointer Offset in GraphicsEPSS 0.8%KEVCVE-2023-33107HIGHInteger Overflow or Wraparound in Graphics LinuxEPSS 0.7%KEVCVE-2024-43047HIGHUse After Free in DSP ServiceEPSS 0.7%KEV