CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Qualcomm critical Wi-Fi flaw reaches car cockpit chips

Qualcomm's August bulletin patches a critical WLAN firmware overflow that reaches Snapdragon automotive cockpit and connectivity chips.

CarThreat Staff
Last updated: August 7, 2026 3:28 pm
By
ctadmin
2 Min Read
SHARE

Qualcomm’s August 2026 security bulletin patches a critical flaw in WLAN firmware that affects a broad range of its chips, including automotive-grade parts used in connected vehicles.

The most severe issue, CVE-2026-25289, is a stack-based buffer overflow rated 9.6 on the CVSS scale. The bug is triggered by malformed Device Capability Extended attributes in certain NAN Service Discovery Frames, causing memory corruption. The attack vector is adjacent, meaning an attacker within Wi-Fi range can exploit it remotely without credentials or user interaction, with full impact on confidentiality, integrity, and availability.

The automotive chips in the affected list include the QCA6696 automotive Wi-Fi 6 solution, the SA8255P and SA8770P cockpit platform families, and other auto-grade parts such as the SA7255P, SA7775P, SA8620P, and SA9000P.

Two related fixes matter for cars too. CVE-2026-24083 is a high-severity untrusted pointer dereference in an automotive security driver, triggered by IOCTL requests with invalid arguments, and affects the SA8295P, QAM8295P, and QCA6696 — including the flagship Snapdragon Cockpit Gen 3 platform built on SA8295P. CVE-2026-21366 is a high-severity integer overflow in the data network stack with the same automotive chipset footprint.

Qualcomm says patches are being actively shared with OEMs, who are responsible for deploying fixes to released vehicles. For drivers, that means the timeline depends on automaker update programs, underscoring why over-the-air update capability is becoming a security feature in itself.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Connected VehiclesCybersecurityFirmware SecurityOTA UpdatesVehicle SoftwareVulnerabilities
SOURCES:Qualcomm
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

CybersecurityEV & Infrastructure

CISA warns of critical flaws in XCharge C6 EV charging stations

By
ctadmin
July 18, 2026
Cybersecurity

4D LiDAR Traffic Platform Chosen for Snowy City Intersections to Improve Road Safety

By
ctadmin
June 12, 2026
iBoy Netflix film scene depicting remote car hacking
Cybersecurity

From Screen to Street: How a Netflix Film Exposes Real Car Hacking Risks

By
ctadmin
May 25, 2026
Cybersecurity

Nvidia Drive Hyperion Becomes Core Platform for Global Robotaxi Expansion

By
ctadmin
June 12, 2026
Cybersecurity

Ethernet flood via OBD port stalls cars and blacks out displays

By
ctadmin
August 6, 2026
Car NewsCybersecurity

Critical buffer overflow in EV charging protocol puts vehicles at risk

By
ctadmin
July 18, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?