Priv Esc via Weak Temp File Handling in Qualcomm Device
CVE-2026-25265 Published on September 22, 2026
Creation of Temporary File with Insecure Permissions in Qualcomm Software Center
Privilege escalation due to weak configuration while temporary file handling.
Vulnerability Analysis
CVE-2026-25265 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Creation of Temporary File With Insecure Permissions
Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack.
Products Associated with CVE-2026-25265
Want to know whenever a new CVE is published for Qualcomm Snapdragon? stack.watch will email you.
Affected Versions
Qualcomm, Inc. Snapdragon:- Version QSCv1.17.1 is affected.
- Version QSCv1.19.1 is affected.
- Version QSCv1.21.0 is affected.
- Version QSCv1.22.1 is affected.
- Version QSCv1.25.1 is affected.
- Version QSCv1.26.0 on Windows is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.