Junglewise Threat Intelligence

CVE-2026-21368: Qualcomm Snapdragon memory corruption in JPEG command parsing

CVE-2026-21368 · Severity: medium · CVSS 5.3 · Published 2026-07-06

Technologies: Qualcomm Fastconnect 6700, Qualcomm, Inc. Snapdragon, Qualcomm Fastconnect 6900, Qualcomm Fastconnect 7800, Qualcomm Sa8255p. Vendors: Qualcomm.

Executive brief

A memory corruption vulnerability exists in several Qualcomm Snapdragon chipsets used in mobile devices, automotive systems, and industrial IoT equipment. An attacker with local access to a device could potentially cause system instability or gain unauthorized access to sensitive memory areas by exploiting how the hardware processes image commands. This could lead to a partial loss of device confidentiality or availability.

Technical details

An out-of-bounds write (CWE-787) exists in Qualcomm Snapdragon firmware during the parsing of JPEG commands. The vulnerability is caused by unaccounted extra writes to a buffer during validation checks, leading to memory corruption. This is a local attack requiring low privileges, though it has high complexity (AC:H). Successful exploitation allows an attacker to impact the integrity, confidentiality, and availability of the system, potentially crossing security boundaries (Scope: Changed). Affected chipsets include various Snapdragon Mobile, Auto, and Compute platforms.

Affected products

  • Qualcomm, Inc. Snapdragon FastConnect 6700, 6900, 7800; G3x Gen 2; IQ9 Series; SA7255P, SA8255P, SA8770P, SD 8 Gen1 5G, and others

Timeline

  • 2026-07-06: advisory: Initial disclosure by Qualcomm and NVD publication.

References

Related threats