PT-2025-44985 · Qualcomm · Qualcomm Gnss Service
Published
2025-11-04
·
Updated
2025-11-15
·
CVE-2025-20746
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Qualcomm GNSS Service (affected versions not specified)
Description
An out-of-bounds write issue exists in the GNSS service due to an incorrect bounds check. Successful exploitation could allow a malicious actor with System privileges to escalate their privileges locally. User interaction is not required for exploitation.
Recommendations
Apply patch ALPS10010441.
Fix
LPE
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qualcomm Gnss Service