Executive brief
A memory corruption vulnerability exists in various Qualcomm Snapdragon chipsets used in mobile devices, IoT platforms, and automotive systems. An attacker with local access to a device could potentially cause system instability or gain unauthorized access to sensitive data. This issue affects the core hardware components responsible for connectivity and processing in millions of consumer electronics.
Technical details
This vulnerability is a Use-After-Free (CWE-416) issue that leads to memory corruption. It occurs when the system processes multiple Input/Output Control (IOCTL) calls that utilize the same buffer file descriptor input simultaneously or in rapid succession. An attacker with low-privileged local access could exploit this race condition or improper reference counting to corrupt system memory. Successful exploitation could allow for a scope cross (S:C), potentially leading to unauthorized information disclosure or elevated execution integrity. The vulnerability affects a wide range of Snapdragon platforms including Mobile, Compute, and Consumer IOT.
Affected products
- Qualcomm, Inc. Snapdragon Mobile FastConnect 6700, FastConnect 6900, FastConnect 7800, QCM5430, QCM6490, SD865 5G, Snapdragon 460, Snapdragon 662, Snapdragon 8 Elite Gen 5, Snapdragon XR2 5G, WCN7880, and others
Timeline
- 2026-07-06: advisory: Published in Qualcomm July 2026 Security Bulletin
- 2026-07-06: disclosed