CVE-2026-25262 is a Qualcomm boot-chain vulnerability in the Primary Bootloader/BootROM environment, specifically in the Sahara protocol used by Emergency Download Mode (EDL). The flaw is a write-what-where condition that can trigger memory corruption while the bootloader processes crafted ELF content delivered during the EDL workflow. The vulnerable logic is associated with validation of chunks from a service program loaded over USB before the operating system starts and before normal user access controls are enforced. Because the issue resides in immutable BootROM code on affected chip families, exploitation occurs at a very early stage of device initialization and can permit arbitrary memory writes in the pre-OS boot context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A related Qualcomm Primary Bootloader memory corruption vulnerability classified as a write-what-where condition.
Уязвимость в BootROM/Primary Boot Loader чипов Qualcomm, связанная с протоколом Sahara в Emergency Download Mode (EDL), позволяющая произвольную запись в память (write-what-where) и потенциально полный контроль над устройством при наличии физического доступа по USB.
A write-what-where vulnerability in the Qualcomm Primary Bootloader that can cause memory corruption when processing crafted ELF files.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.