PT-2025-44985 · Qualcomm · Qualcomm Gnss Service

Published

2025-11-04

·

Updated

2025-11-15

·

CVE-2025-20746

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Qualcomm GNSS Service (affected versions not specified)
Description An out-of-bounds write issue exists in the GNSS service due to an incorrect bounds check. Successful exploitation could allow a malicious actor with System privileges to escalate their privileges locally. User interaction is not required for exploitation.
Recommendations Apply patch ALPS10010441.

Fix

LPE

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-20746

Affected Products

Qualcomm Gnss Service