Executive brief
A memory corruption vulnerability exists in Qualcomm chipset software, which is used to power a wide range of mobile devices and embedded systems. An attacker with local access to a device could exploit this flaw to crash the system or potentially gain unauthorized access to sensitive data. This could lead to a total compromise of the device's security and operational integrity.
Technical details
A NULL pointer dereference (CWE-476) exists in Qualcomm firmware/software during memory copy operations. The vulnerability is triggered when the system attempts to perform an invalid write operation using a null pointer, leading to memory corruption. An attacker with local access and low privileges can exploit this to achieve high impact on confidentiality, integrity, and availability. The issue was disclosed in the June 2026 Qualcomm Security Bulletin. Mitigation typically requires applying firmware updates provided by the device manufacturer.
Affected products
- Qualcomm Snapdragon Mobile
Timeline
- 2026-06-01: advisory: Published in Qualcomm June 2026 Security Bulletin
- 2026-06-01: disclosed