CVE-2026-25255

8.8

Qualcomm · Snapdragon

An exposed dangerous function in the gRPC server component of Qualcomm Snapdragon allows local attackers to achieve privilege escalation.

Executive summary

A high-severity privilege escalation vulnerability in the Qualcomm Snapdragon gRPC server exposes systems to unauthorized control by local authenticated users.

Vulnerability

The vulnerability, classified as CWE-749, involves an exposed dangerous method within the gRPC server interface, which can be triggered by a local attacker with low privileges.

Business impact

Successful exploitation of this flaw grants an attacker elevated privileges, potentially leading to full system compromise. With a CVSS score of 8.8, this vulnerability poses a significant threat to data integrity, confidentiality, and system availability, necessitating immediate attention to prevent unauthorized administrative actions.

Remediation

Immediate Action: Review the official Qualcomm security bulletin for May 2026 to identify and apply the necessary firmware or software updates to the affected Snapdragon components.

Proactive Monitoring: Monitor system logs for unusual gRPC service calls or unexpected attempts to execute privileged commands from non-privileged user accounts.

Compensating Controls: Implement strict local access control policies and restrict user interaction with the gRPC interface to minimize the attack surface until patches are verified and applied.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for full system compromise, organizations using the affected Qualcomm Snapdragon versions must prioritize this update. Security teams should verify their hardware inventory against the listed affected versions and coordinate with the vendor to secure their infrastructure against potential local privilege escalation attempts.

More Qualcomm CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources