CVE-2025-59606

HIGH

Qualcomm Snapdragon HLOS - Secure Data Initialization Null Pointer Dereference

Title source: manual
STIX 2.1

Description

Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 0.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-476
Status published
Products (50)
qualcomm/cologne_firmware
qualcomm/cq7790_firmware
qualcomm/cq8725s_firmware
qualcomm/cq8750m_firmware
qualcomm/fastconnect_6200_firmware
qualcomm/fastconnect_6700_firmware
qualcomm/fastconnect_6900_firmware
qualcomm/fastconnect_7800_firmware
qualcomm/g2_gen_1_firmware
qualcomm/iq-615_firmware
... and 40 more
Published Jun 01, 2026
Tracked Since Jun 02, 2026