Junglewise Threat Intelligence

CVE-2026-21369: Qualcomm Snapdragon memory corruption in flash command handling

CVE-2026-21369 · Severity: medium · CVSS 5.3 · Published 2026-07-06

Technologies: Qualcomm, Inc. Snapdragon Compute, Qualcomm, Inc. Snapdragon Auto, Qualcomm, Inc. Snapdragon Mobile, Qualcomm, Inc. Snapdragon Wearables, Qualcomm, Inc. Snapdragon Industrial IOT, Qualcomm, Inc. Snapdragon Consumer IOT.

Executive brief

A memory corruption vulnerability exists in various Qualcomm Snapdragon chipsets, which are used in mobile phones, automotive systems, and IoT devices. An attacker with local access to a device could exploit this flaw to interfere with the device's internal operations or potentially gain unauthorized access to sensitive data. This could lead to system instability or a compromise of the device's security protections.

Technical details

This vulnerability is classified as an Out-of-bounds Write (CWE-787) within the firmware handling flash commands. The root cause is a synchronization issue where outdated LED count values are utilized after they have been modified by userspace, leading to memory corruption. An attacker with low-privileged local access can exploit this flaw, though the attack complexity is high. Successful exploitation can result in a scope change, potentially allowing the attacker to impact the integrity, confidentiality, and availability of the system. Qualcomm has addressed this in their July 2026 security bulletin.

Affected products

  • Qualcomm, Inc. Snapdragon Mobile FastConnect 6200, 6700, 6900, 7800, G1 Gen 1, G3x Gen 2, IQ9 Series, QCM2290, QCM4490, QCM6490, QCS2290, QCS4490, and others
  • Qualcomm, Inc. Snapdragon Auto
  • Qualcomm, Inc. Snapdragon Compute
  • Qualcomm, Inc. Snapdragon Consumer IOT
  • Qualcomm, Inc. Snapdragon Industrial IOT
  • Qualcomm, Inc. Snapdragon Wearables

Timeline

  • 2026-07-06: advisory: Qualcomm published the security bulletin and CVE details.

References