CVE-2026-25302: high-severity vulnerability in Qualcomm, Inc. Snapdragon
Improper Verification of Cryptographic Signature in Boot
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.1%
exploitation probability
0.1%top 100% of all CVEs
observed exploitation
nono source reports it
Cryptographic Issue when processing non-ELF partitions, authentication and signature checks are bypassed, allowing unsigned or corrupted images to be mounted and processed.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Affected products
Qualcomm, Inc. · SnapdragonRelated CVEs — Qualcomm, Inc. Snapdragon
In the same product, most dangerous first.
CVE-2026-21385HIGHInteger Overflow or Wraparound in GraphicsEPSS 1.3%KEVCVE-2025-27038HIGHUse After Free in GraphicsEPSS 1.0%KEVCVE-2025-21479HIGHIncorrect Authorization in GraphicsEPSS 0.8%KEVCVE-2023-33106HIGHUse of Out-of-range Pointer Offset in GraphicsEPSS 0.8%KEVCVE-2023-33107HIGHInteger Overflow or Wraparound in Graphics LinuxEPSS 0.7%KEVCVE-2024-43047HIGHUse After Free in DSP ServiceEPSS 0.7%KEV