Executive brief
A security vulnerability exists in various Qualcomm Snapdragon processors and components used in laptops, mobile devices, and industrial IoT equipment. An attacker with local access to a device could exploit this flaw to corrupt system memory, potentially leading to a full system takeover or the theft of sensitive information. This affects the core hardware responsible for processing data and managing wireless connections.
Technical details
A memory corruption vulnerability exists in multiple Qualcomm Snapdragon chipsets, including Compute and Industrial IOT platforms, due to improper validation of memory allocation sizes. Specifically, the system fails to correctly handle allocation requests that exceed maximum allowed values, leading to a buffer over-read (CWE-126) or related memory corruption. The attack vector is local, requiring low privileges and no user interaction. Successful exploitation can result in a total impact on confidentiality, integrity, and availability. A fix is available via the Qualcomm July 2026 security bulletin.
Affected products
- Qualcomm, Inc. Snapdragon Compute AQT1000, Cologne, FastConnect 6200, FastConnect 6700, FastConnect 6800, FastConnect 6900, FastConnect 7800, IQX5121, IQX7181, QCA0000, QCA6391, QCA6420, QCA6430, QCM5430, QCM6490, SC8380XP, Snapdragon 7c+ Gen 3, Snapdragon 8c, Snapdragon 8cx, Snapdragon 8cx Gen 2, Snapdragon 8cx Gen 3
- Qualcomm, Inc. Snapdragon Industrial IOT WCD9340, WCD9341, WCD9370, WCD9375, WCD9378C, WCD9380, WCD9385, WSA8810, WSA8815, WSA8830, WSA8835
- Qualcomm, Inc. Qualcomm Video Collaboration VC3 Platform Affected
Timeline
- 2026-07-06: advisory: Qualcomm published the security bulletin and NVD record.