CVE-2026-25262Disclosure

LOW

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

1.8/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 13 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 9 signals
  • Disclosure: 11 classified signals
  • General: 2 classified signals
  • Peaked 8d ago at 2 mentions (2026-05-05); latest day: 2
  • 13 total mentions across 11 days

Deep dive

Activity timeline13 mentions / 11d
01122Mentions · 2026-04-23: 1Mentions · 2026-04-25: 1Mentions · 2026-05-05: 2Mentions · 2026-05-22: 1Mentions · 2026-06-02: 1Mentions · 2026-06-03: 1Mentions · 2026-06-23: 1Mentions · 2026-06-30: 1Mentions · 2026-07-29: 1Mentions · 2026-08-23: 1Mentions · 2026-09-22: 2PoC Mentioned / Linked · 2026-08-23: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-25: 1Technical Details · 2026-05-05: 2Technical Details · 2026-06-02: 1Technical Details · 2026-06-03: 1Technical Details · 2026-07-29: 1Technical Details · 2026-08-23: 1Technical Details · 2026-09-22: 104-2304-2505-0505-2206-0206-0306-2306-3007-2908-2309-22
Signal classification2 categories
Disclosure
1184.6%
General
215.4%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-04-251
Disclosure1
2026-05-052
Disclosure2
2026-05-221
General1
2026-06-021
Disclosure1
2026-06-031
Disclosure1
2026-06-231
Disclosure1
2026-06-301
General1
2026-07-291
Disclosure1
2026-08-231
Disclosure1
2026-09-222
Disclosure2
Full discourse13 posts
  • zip@zippgod24
    General

    Samsung S20/S20+/S20 Ultra, leveraging a bootrom vulnerability in the Qualcomm SM8250 (Snapdragon 865 “Kona”) chipset anyone happen to know which they might be referring to maybe this CVE-2026-25262 ? Anyone have any idea

    Post summary

    The text merely raises a question about a suspected CVE (2026-25262) affecting Snapdragon 865 devices, without providing additional technical or exploitation details.

    200641.7K
    1.9K followersView on X
  • XiaomiTime@timexiaomi
    Disclosure

    Snapdragon chips hit by hardware-level flaw at boot ROM. 🚨 - CVE-2026-25262 exposed at Black Hat Asia 2026 - Physical access needed; full device compromise possible - Affects legacy/mid-range chipsets (MDM, MSM系列) - Hard to patch; OTA updates ineffec… https://ift.tt/LkwYUT0

    Post summary

    The text announces the exposure of a hardware-level flaw in Snapdragon boot ROM (CVE-2026-25262) at Black Hat Asia 2026, highlighting its requirement for physical access and the difficulty of patching legacy/mid‑range chipsets.

    000110586
    12.3K followersView on X
  • it security@it__security
    Disclosure

    Durch die neu entdeckte #Qualcomm-Schwachstelle CVE-2026-25262 können #Hacker den Secure Boot umgehen und #Smartphone-Kameras unbemerkt aktivieren. https://www.it-daily.net/it-sicherheit/cybercrime/smartphone-vortaeuschen

    Post summary

    A new Qualcomm vulnerability (CVE-2026-25262) is disclosed, enabling hackers to bypass Secure Boot and secretly activate smartphone cameras. No PoC, exploit code, patch, or active exploitation evidence is provided.

    01252318
    5.4K followersView on X
  • Henry Raúl Glez Brito@henryraul
    Disclosure

    1/ @KasperskyES alerta sobre vulnerabilidad de #ciberseguridad CVE‑2026‑25262 que afecta a ciertos chips Qualcomm y permite escalada de privilegios en el dispositivo. Requiere acceso previo al sistema para su explotación: https://www.kaspersky.es/blog/qualcomm-cve-2026-25262/32155/ @Qualcomm o @KasperskyLatino

    Post summary

    Kaspersky reports a privilege‑escalation vulnerability (CVE‑2026‑25262) affecting certain Qualcomm chips, highlighting that prior local access is needed for exploitation.

    13021237
    11.2K followersView on X
  • Евгений Касперский@e_kaspersky_ru
    General

    Наши эксперты обнаружили неисправимую уязвимость в чипах Qualcomm (CVE-2026-25262), которые широко используются в смартфонах, автомобилях и IoT. Для эксплуатации нужен физический доступ к устройству. Подробности: https://kas.pr/xh3d https://t.co/sIp0J8zJQH

    Post summary

    Experts announced a critical, irreparable Qualcomm chip vulnerability that requires physical access, with more details available via provided links.

    03022461
    24.2K followersView on X
  • Kaspersky España@KasperskyES
    Disclosure

    ⚠️ Hemos descubierto una vulnerabilidad crítica en chips Qualcomm (CVE-2026-25262) que afecta a millones de dispositivos, desde smartphones hasta equipos IoT y sistemas de automoción. El fallo reside en el BootROM, una parte del chip imposible de actualizar una vez fabricada. 👀👉 https://kas.pr/w418

    Post summary

    The tweet announces the discovery of CVE-2026-25262, a critical flaw in the un-updatable BootROM of Qualcomm chips that could affect millions of devices.

    01040523
    27.0K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🔴 Qualcomm çiplerinde kritik BootROM açığı: Güvenlik kontrolleri aşılabiliyor! Kaspersky araştırmacıları Alexander Kozlov ve Sergey Anufrienko, Qualcomm'un MSM/MDM ailesindeki SoC'leri inceleyerek CVE-2026-25262 adlı kritik güvenlik açığını ortaya çıkardı. Araştırmacılar, özellikle MDM9207 üzerinde Emergency Download Mode (EDL) kapsamında kullanılan Sahara protokolünü analiz etti. BootROM seviyesindeki CWE-123 (Write-What-Where) açığı sayesinde güvenlik kontrollerinin aşılabildiği ve Secure Boot zincirinin kırılarak çip üzerinde tam kontrol elde edilebildiği gösterildi. Açık; MDM9x07, MDM9x45, MDM9x65, MSM8909, MSM8916, MSM8952 ve SDX50 serilerini etkiliyor. Bu platformlar akıllı telefonların yanı sıra IoT cihazları, endüstriyel sistemler ve otomotiv çözümlerinde de kullanılıyor. En kritik nokta ise açığın BootROM'da bulunması. BootROM çip üretildikten sonra değiştirilemediği için mevcut donanımlarda klasik bir yazılım güncellemesiyle tamamen giderilemiyor. Saldırı için fiziksel erişim gerekiyor; örneğin cihazın bir servis merkezinde saldırgana bırakılması gibi senaryolar risk oluşturuyor. Qualcomm BootROM: A Journey Through Sahara araştırmasının teknik sunumu Black Hat Asia 2026'da yayınlandı. Sunum: https://www.youtube.com/watch?v=ZlWvdRBuxpc Teknik anlatım: https://i.blackhat.com/Asia-26/Presentations/BHAS26-Kozlov-Anufrienko-Qualcom-REV01.pdf

    Post summary

    Qualcomm researchers disclosed CVE‑2026‑25262, a critical BootROM Write‑What‑Where flaw that bypasses Secure Boot via physical access; detailed technical findings were presented at Black Hat but no patch or exploit code is available.

    01012409
    1.9K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Qualcomm Snapdragon Auto and other products (CVE-2026-25262) https://vuldb.com/vuln/408395

    Post summary

    The message announces CVE-2026-25262 affecting Qualcomm Snapdragon Auto and other products, linking to a VulDB entry for more information. No exploit, PoC, patch, or active exploitation details are included.

    01010151
    2.3K followersView on X
  • Kaspersky España@KasperskyES
    Disclosure

    ⚠️ Hemos descubierto una vulnerabilidad crítica en chips Qualcomm (CVE-2026-25262) que afecta a millones de dispositivos, desde smartphones hasta equipos IoT y sistemas de automoción. El fallo reside en el BootROM, una parte del chip imposible de actualizar una vez fabricada. 👀👉 https://kas.pr/w418

    Post summary

    The post announces the discovery of a critical CVE-2026-25262 affecting Qualcomm chips, noting the vulnerability lies in the unupdatable BootROM and impacts millions of devices.

    00020317
    27.0K followersView on X
  • Kaspersky España@KasperskyES
    Disclosure

    ⚠️ Hemos descubierto una vulnerabilidad crítica en chips Qualcomm (CVE-2026-25262) que afecta a millones de dispositivos, desde smartphones hasta equipos IoT y sistemas de automoción. El fallo reside en el BootROM, una parte del chip imposible de actualizar una vez fabricada. 👀👉 https://kas.pr/w418

    Post summary

    A critical CVE-2026-25262 affecting Qualcomm chips’ immutable BootROM has been discovered, impacting millions of devices from smartphones to IoT and automotive systems.

    00020666
    27.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25262 Memory corruption while processing a crafted ELF file in the Primary Bootloader. https://www.cve.org/CVERecord?id=CVE-2026-25262

    Post summary

    The tweet announces CVE‑2026‑25262, describing a memory corruption vulnerability in the Primary Bootloader triggered by a crafted ELF file, and links to the official CVE record.

    000001.4K
    58.1K followersView on X
  • Reiner Aber Ja@ReinerAberJa
    Disclosure

    Durch die neu entdeckte Qualcomm-Schwachstelle CVE-2026-25262 können Hacker den Secure Boot umgehen und Smartphone-Kameras unbemerkt aktivieren... Link https://us.list-manage.com/a3FV9b9fAVI?e=925f5abdfe&c2id=e8e4a461e6d75693582078994d25390c

    Post summary

    The article announces a newly discovered Qualcomm vulnerability (CVE-2026-25262) that can bypass Secure Boot and activate smartphone cameras undetected.

    0000046
    1.2K followersView on X
  • Roberto Cosentino@robytenk
    Disclosure

    New CVE-2026-25262 hits Qualcomm Snapdragon BootROM via Sahara in EDL, enabling physical attackers to bypass secure boot, access data, and possibly take control. Affects several Snapdragon chips; supply-chain risk. #Security #Qualcomm https://ift.tt/21c8ymC

    Post summary

    CVE-2026-25262 exploits a flaw in Qualcomm Snapdragon BootROM via Sahara in EDL, allowing physical attackers to bypass secure boot and potentially gain full control of affected chips.

    0000064
    443 followersView on X

Explore more