


Perceptive Security
SOC/SIEM Consultancy

Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
Published:
3 augustus 2026 om 22:00:00
Alert date:
4 augustus 2026 om 17:02:19
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
CVE-2026-25289 is a memory corruption vulnerability affecting Qualcomm chipsets during the processing of Device Capability Extended attributes in NAN (Neighbor Awareness Networking) Service Discovery Frames. The flaw is triggered when frames contain invalid length values, potentially allowing an attacker to corrupt memory. This type of vulnerability can lead to arbitrary code execution or denial of service depending on exploitation context. The issue was disclosed via the NVD and is detailed in Qualcomm's August 2026 Security Bulletin. NAN is a Wi-Fi protocol feature used for device discovery without requiring a traditional network connection, making this a wireless attack surface concern. The vulnerability is rated High criticality.
Technical details
Mitigation steps:
Affected products:
Qualcomm NAN Service Discovery
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-25289
https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
