CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Qualcomm critical Wi-Fi flaw reaches car cockpit chips

Qualcomm's August bulletin patches a critical WLAN firmware overflow that reaches Snapdragon automotive cockpit and connectivity chips.

CarThreat Staff
Last updated: August 7, 2026 3:28 pm
By
ctadmin
2 Min Read
SHARE

Qualcomm’s August 2026 security bulletin patches a critical flaw in WLAN firmware that affects a broad range of its chips, including automotive-grade parts used in connected vehicles.

The most severe issue, CVE-2026-25289, is a stack-based buffer overflow rated 9.6 on the CVSS scale. The bug is triggered by malformed Device Capability Extended attributes in certain NAN Service Discovery Frames, causing memory corruption. The attack vector is adjacent, meaning an attacker within Wi-Fi range can exploit it remotely without credentials or user interaction, with full impact on confidentiality, integrity, and availability.

The automotive chips in the affected list include the QCA6696 automotive Wi-Fi 6 solution, the SA8255P and SA8770P cockpit platform families, and other auto-grade parts such as the SA7255P, SA7775P, SA8620P, and SA9000P.

Two related fixes matter for cars too. CVE-2026-24083 is a high-severity untrusted pointer dereference in an automotive security driver, triggered by IOCTL requests with invalid arguments, and affects the SA8295P, QAM8295P, and QCA6696 — including the flagship Snapdragon Cockpit Gen 3 platform built on SA8295P. CVE-2026-21366 is a high-severity integer overflow in the data network stack with the same automotive chipset footprint.

Qualcomm says patches are being actively shared with OEMs, who are responsible for deploying fixes to released vehicles. For drivers, that means the timeline depends on automaker update programs, underscoring why over-the-air update capability is becoming a security feature in itself.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Connected VehiclesCybersecurityFirmware SecurityOTA UpdatesVehicle SoftwareVulnerabilities
SOURCES:Qualcomm
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

T-Systems Builds Dedicated Private Cloud for Volkswagen Group to Centralize App Infrastructure

By
ctadmin
July 2, 2026
Cybersecurity

The Hidden Security Risk in Car Recycling: How OBD Commands Expose Connected Vehicles

By
ctadmin
May 22, 2026
Cybersecurity

Volvo EX60 Camera Feed Gets Real Time AI Interpretation via Google Gemini

By
ctadmin
May 24, 2026
Cybersecurity

Uber and Wayve Launch London Robotaxi Service with Mapless AI System

By
ctadmin
June 12, 2026
CybersecurityEV & Infrastructure

CISA warns of critical flaws in XCharge C6 EV charging stations

By
ctadmin
July 18, 2026
Cybersecurity

Hyundai Mobis Contributes Container Tech to Eclipse SDV Open Source Project

By
ctadmin
May 29, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Autonomous Driving
  • Pwn2Own Automotive
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?