Executive brief
A security vulnerability exists in Qualcomm chipsets used in many mobile devices. The flaw occurs when the system processes device identification information that is longer than expected, leading to memory corruption. If exploited, a malicious application already on the device could gain deeper access, potentially compromising user data or taking control of core system functions.
Technical details
A memory corruption vulnerability, specifically an out-of-bounds write (CWE-787), exists in Qualcomm firmware/software during the processing of device identifier strings. The issue is triggered when a string exceeds the statically defined buffer length, allowing an attacker to overwrite adjacent memory. This is a local attack requiring low privileges, typically achieved through a malicious application running on the host OS. Successful exploitation can lead to a complete loss of confidentiality, integrity, and availability at the firmware or kernel level. Qualcomm has addressed this in their June 2026 security bulletin.
Affected products
- Qualcomm Snapdragon Mobile
Timeline
- 2026-06-01: advisory: Qualcomm published the security bulletin and NVD entry.