Executive brief
A security vulnerability exists in the diagnostic services of Qualcomm chipsets, which are used to monitor and troubleshoot device performance. An attacker with high-level administrative access could exploit this flaw to corrupt system memory, potentially leading to a complete system crash or unauthorized access to sensitive data. This could disrupt device operations and compromise the integrity of the underlying hardware platform.
Technical details
A memory corruption vulnerability exists in Qualcomm diagnostic services due to an out-of-bounds write (CWE-787) caused by a lack of proper input validation. The vulnerability is exploitable locally by an attacker with high privileges (PR:H), requiring no user interaction. Successful exploitation allows the attacker to corrupt memory, which can lead to a loss of confidentiality, integrity, and availability of the affected system. The issue was disclosed in the June 2026 Qualcomm Security Bulletin.
Affected products
- Qualcomm Snapdragon
Timeline
- 2026-06-01: advisory: Published in Qualcomm June 2026 Security Bulletin
- 2026-06-01: disclosed