Qualcomm’s August 2026 security bulletin patches a critical flaw in WLAN firmware that affects a broad range of its chips, including automotive-grade parts used in connected vehicles.
The most severe issue, CVE-2026-25289, is a stack-based buffer overflow rated 9.6 on the CVSS scale. The bug is triggered by malformed Device Capability Extended attributes in certain NAN Service Discovery Frames, causing memory corruption. The attack vector is adjacent, meaning an attacker within Wi-Fi range can exploit it remotely without credentials or user interaction, with full impact on confidentiality, integrity, and availability.
The automotive chips in the affected list include the QCA6696 automotive Wi-Fi 6 solution, the SA8255P and SA8770P cockpit platform families, and other auto-grade parts such as the SA7255P, SA7775P, SA8620P, and SA9000P.
Two related fixes matter for cars too. CVE-2026-24083 is a high-severity untrusted pointer dereference in an automotive security driver, triggered by IOCTL requests with invalid arguments, and affects the SA8295P, QAM8295P, and QCA6696 — including the flagship Snapdragon Cockpit Gen 3 platform built on SA8295P. CVE-2026-21366 is a high-severity integer overflow in the data network stack with the same automotive chipset footprint.
Qualcomm says patches are being actively shared with OEMs, who are responsible for deploying fixes to released vehicles. For drivers, that means the timeline depends on automaker update programs, underscoring why over-the-air update capability is becoming a security feature in itself.