top of page
perceptive_background_267k.jpg

Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

Published:

3 augustus 2026 om 22:00:00

Alert date:

4 augustus 2026 om 17:02:19

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure

CVE-2026-25289 is a memory corruption vulnerability affecting Qualcomm chipsets during the processing of Device Capability Extended attributes in NAN (Neighbor Awareness Networking) Service Discovery Frames. The flaw is triggered when frames contain invalid length values, potentially allowing an attacker to corrupt memory. This type of vulnerability can lead to arbitrary code execution or denial of service depending on exploitation context. The issue was disclosed via the NVD and is detailed in Qualcomm's August 2026 Security Bulletin. NAN is a Wi-Fi protocol feature used for device discovery without requiring a traditional network connection, making this a wireless attack surface concern. The vulnerability is rated High criticality.

Technical details

Mitigation steps:

Affected products:

Qualcomm NAN Service Discovery

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page