Skip to main content
Mallory
High

Memory corruption in Qualcomm Strongbox due to missing bounds check

IdentifiersCVE-2026-25276CWE-129· Improper Validation of Array Index

CVE-2026-25276 is a critical memory corruption vulnerability in a Qualcomm closed-source Strongbox component. According to the provided content, the flaw is caused by a missing bounds check, which can result in out-of-bounds memory access and corruption during Strongbox use. Qualcomm assigned CWE-129 to the issue. The available context does not identify the specific vulnerable function or code path, but it does establish that the bug resides in Strongbox and stems from improper validation of bounds before memory operations.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can cause memory corruption in the affected Strongbox component. Based on the provided CVSS v3.1 vector (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), the vulnerability can have high impact on confidentiality, integrity, and availability, with changed scope. In practical terms, exploitation could enable compromise of the affected component, including potential access to sensitive data, unauthorized modification of data or execution state, and denial of service through crashes or instability. The exact post-exploitation behavior is not further specified in the provided content.

Mitigation

If you can’t patch tonight, do this now.

If the patch cannot be applied immediately, reduce exposure by limiting local access to the device, restricting untrusted code execution, and minimizing the ability of low-privileged local actors to interact with the affected component. Prioritize installation of OEM security updates carrying the 2026-06-05 Android security patch level or later. Because the issue affects a closed-source Qualcomm component, no specific configuration workaround is provided in the available content.

Remediation

Patch, then assume compromise.

Apply the Qualcomm-provided fix referenced in the June 2026 Qualcomm security bulletin and deploy Android security updates that include the relevant vendor patch. The provided content indicates this issue is addressed in Google’s June 2026 Android security release, specifically in the 2026-06-05 security patch level that includes Qualcomm closed-source component fixes. Use vendor/OEM firmware incorporating the patched Qualcomm binaries.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
QualcommCq8750m Firmwareoperating_system
QualcommFastconnect 6700 Firmwareoperating_system
QualcommFastconnect 6800 Firmwareoperating_system
QualcommFastconnect 6900 Firmwareoperating_system
QualcommFastconnect 7800 Firmwareoperating_system
QualcommG3x Gen 2 Firmwareoperating_system
QualcommPandeiro Firmwareoperating_system
QualcommQca6391 Firmwareoperating_system
QualcommQca6698au Firmwareoperating_system
QualcommQca6797aq Firmwareoperating_system
QualcommQcm5430 Firmwareoperating_system
QualcommQcm6490 Firmwareoperating_system
QualcommQcm8838 Firmwareoperating_system
QualcommQcn9011 Firmwareoperating_system
QualcommQcn9012 Firmwareoperating_system
QualcommQcs8550 Firmwareoperating_system
QualcommSd865 5g Firmwareoperating_system
QualcommSdr753 Firmwareoperating_system
QualcommSm8550p Firmwareoperating_system
QualcommSm8650q Firmwareoperating_system
QualcommSm8750p Firmwareoperating_system
QualcommSnapdragon 460 Mobile Platform Firmwareoperating_system
QualcommSnapdragon 662 Mobile Platform Firmwareoperating_system
QualcommSnapdragon 8 Elite Firmwareoperating_system
QualcommSnapdragon 8 Elite Gen 5 Firmwareoperating_system
QualcommSnapdragon 8 Gen 2 Mobile Platform Firmwareoperating_system
QualcommSnapdragon 8 Gen 3 Mobile Platform Firmwareoperating_system
QualcommSnapdragon 8+ Gen 2 Mobile Platform Firmwareoperating_system
QualcommSnapdragon 865 5g Mobile Platform Firmwareoperating_system
QualcommSnapdragon 865+ 5g Mobile Platform Firmwareoperating_system
QualcommSnapdragon 870 5g Mobile Platform Firmwareoperating_system
QualcommSnapdragon Ar1 Gen 1 Platform Firmwareoperating_system
QualcommSnapdragon X55 5g Modem-Rf System Firmwareoperating_system
QualcommSnapdragon Xr2 5g Platform Firmwareoperating_system
QualcommSnapdragon Xr2+ Gen 1 Platform Firmwareoperating_system
QualcommVideo Collaboration Vc3 Platform Firmwareoperating_system
QualcommWcd9370 Firmwareoperating_system
QualcommWcd9375 Firmwareoperating_system
QualcommWcd9380 Firmwareoperating_system
QualcommWcd9385 Firmwareoperating_system
QualcommWcd9390 Firmwareoperating_system
QualcommWcd9395 Firmwareoperating_system
QualcommWcn3950 Firmwareoperating_system
QualcommWcn3988 Firmwareoperating_system
QualcommWcn7760 Firmwareoperating_system
QualcommWcn7860 Firmwareoperating_system
QualcommWcn7861 Firmwareoperating_system
QualcommWcn7880 Firmwareoperating_system
QualcommWcn7881 Firmwareoperating_system
QualcommWsa8810 Firmwareoperating_system
QualcommWsa8815 Firmwareoperating_system
QualcommWsa8830 Firmwareoperating_system
QualcommWsa8832 Firmwareoperating_system
QualcommWsa8835 Firmwareoperating_system
QualcommWsa8840 Firmwareoperating_system
QualcommWsa8845 Firmwareoperating_system
QualcommWsa8845h Firmwareoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity7

Community discussion across Reddit, Mastodon, and other social sources.