Executive brief
A memory corruption vulnerability exists in Qualcomm chipsets during the initialization of secure data. An attacker with local access to a device could exploit this flaw to crash the system or potentially gain unauthorized access to sensitive information. This impact compromises the integrity and confidentiality of the device's secure processing environment.
Technical details
A memory corruption vulnerability, specifically identified as a NULL pointer dereference (CWE-476), occurs in Qualcomm firmware during secure data initialization. The flaw is triggered by heap memory exhaustion, which leads the system to attempt writes to invalid memory locations. An attacker with local low-privileged access can exploit this to cause a denial-of-service (system crash) or achieve arbitrary code execution within a privileged context. The vulnerability was disclosed in the June 2026 Qualcomm Security Bulletin.
Affected products
- Qualcomm Snapdragon Mobile
Timeline
- 2026-06-01: advisory: Qualcomm published the security bulletin and NVD entry.