← Vulnerability feed

Vulnerability record · CVE-2026-25272 · published 6 October 2026

CVE-2026-25272: Qualcomm snapdragon g1 gen 2 gaming platform firmware out-of-bounds write vulnerability

Qualcomm · Snapdragon G1 Gen 2 Gaming Platform Firmware

Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation.

6.7 CVSS 3.1 Medium EPSS 0.11% · top 98.6% CWE-787 · Out-of-bounds write
6.7CVSS 3.1 base score
0.11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
150Affected product versions listed by NVD
1References
9 Oct 2026Last modified by NVD

Description

Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-25272 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2026-25289Qualcomm sm7550p firmware stack-based buffer overflow vulnerabilityMemory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.EPSS 0.19%8.8CVE-2026-25283Qualcomm cologne firmware stack-based buffer overflow vulnerabilityMemory Corruption when copying unverified data from an external source exceeds the allocated buffer size.EPSS 0.07%8.8CVE-2026-25276Qualcomm cq8750m firmware vulnerabilityMemory corruption while using Strongbox due to missing bounds check.EPSS 0.08%8.8CVE-2026-25277Qualcomm cq8750m firmware classic buffer overflow vulnerabilityMemory corruption while using Strongbox due to buffer overflow.EPSS 0.07%7.9CVE-2026-25282Qualcomm cologne firmware out-of-bounds read vulnerabilityTransient DOS when processing unverified data from a neighboring system causes out of bound memory access.EPSS 0.06%7.8CVE-2026-57559Qualcomm cologne firmware use after free vulnerabilityMemory corruption while processing service requests.EPSS 0.11%7.8CVE-2026-57545Qualcomm snapdragon g1 gen 2 gaming platform firmware vulnerabilityMemory corruption when processing draw objects of incorrect type during graphics command list execution.EPSS 0.12%7.8CVE-2026-57555Qualcomm cologne firmware use after free vulnerabilityMemory Corruption when executing system service routines due to improper handling of user input buffers.EPSS 0.11%

Source: NIST National Vulnerability Database (record CVE-2026-25272), CISA KEV, FIRST EPSS (scores of 2026-10-09). This page is refreshed as NVD updates the record.