CVE-2026-25264

8.8

Qualcomm · Snapdragon

Qualcomm Snapdragon contains a privilege escalation vulnerability due to a weak configuration during the package extraction process, allowing for uncontrolled search path element exploitation.

Executive summary

A privilege escalation vulnerability in Qualcomm Snapdragon on Windows may allow local attackers to gain elevated system privileges.

Vulnerability

This vulnerability, categorized as CWE-427 (Uncontrolled Search Path Element), occurs during the package extraction process. An attacker with low-level local access can exploit this weak configuration to execute arbitrary code with higher privileges.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating high severity. Successful exploitation allows a local user to escalate privileges, potentially leading to full system compromise, unauthorized data access, and the ability to disable security controls. This poses a significant risk to organizational endpoints running the affected Snapdragon software.

Remediation

Immediate Action: Review the official Qualcomm security bulletin for the release of a patched version and apply updates to affected Windows systems immediately.

Proactive Monitoring: Monitor system logs for unauthorized attempts to modify or execute files within the application's installation directories.

Compensating Controls: Restrict local user permissions to prevent unauthorized access to sensitive directories used by the package extraction process.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for total system compromise, organizations should prioritize patching affected Snapdragon versions. Administrators must monitor the Qualcomm security portal for the availability of a specific fix and deploy it across all vulnerable Windows endpoints as soon as it is released.

More Qualcomm CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Analyst report updated
  5. Published in the daily brief high section

Sources