PT-2025-44985 · Qualcomm · Qualcomm Gnss Service

CVE-2025-20746

·

Published

2025-11-04

·

Updated

2025-11-15

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Qualcomm GNSS Service (affected versions not specified)
Description An out-of-bounds write issue exists in the GNSS service due to an incorrect bounds check. Successful exploitation could allow a malicious actor with System privileges to escalate their privileges locally. User interaction is not required for exploitation.
Recommendations Apply patch ALPS10010441.

Fix

LPE

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-20746

Affected Products

Qualcomm Gnss Service