Executive brief
A memory corruption vulnerability exists in various Qualcomm Snapdragon chipsets, which are used in mobile phones, automotive systems, and IoT devices. An attacker with local access to a device could exploit this flaw to interfere with the device's internal operations or potentially gain unauthorized access to sensitive data. This could lead to system instability or a compromise of the device's security protections.
Technical details
This vulnerability is classified as an Out-of-bounds Write (CWE-787) within the firmware handling flash commands. The root cause is a synchronization issue where outdated LED count values are utilized after they have been modified by userspace, leading to memory corruption. An attacker with low-privileged local access can exploit this flaw, though the attack complexity is high. Successful exploitation can result in a scope change, potentially allowing the attacker to impact the integrity, confidentiality, and availability of the system. Qualcomm has addressed this in their July 2026 security bulletin.
Affected products
- Qualcomm, Inc. Snapdragon Mobile FastConnect 6200, 6700, 6900, 7800, G1 Gen 1, G3x Gen 2, IQ9 Series, QCM2290, QCM4490, QCM6490, QCS2290, QCS4490, and others
- Qualcomm, Inc. Snapdragon Auto
- Qualcomm, Inc. Snapdragon Compute
- Qualcomm, Inc. Snapdragon Consumer IOT
- Qualcomm, Inc. Snapdragon Industrial IOT
- Qualcomm, Inc. Snapdragon Wearables
Timeline
- 2026-07-06: advisory: Qualcomm published the security bulletin and CVE details.