Junglewise Threat Intelligence

CVE-2026-21383: Qualcomm Snapdragon Cryptographic Issue in AES-GCM key wrapping

CVE-2026-21383 · Severity: high · CVSS 7.1 · Published 2026-07-06

Technologies: Qualcomm, Inc. Snapdragon, Qualcomm Qca6595au, Qualcomm Fastconnect 6900, Qualcomm Qca6696, Qualcomm Fastconnect 7800, Qualcomm Sa8255p. Vendors: Qualcomm.

Executive brief

A security flaw exists in several Qualcomm Snapdragon chipsets used in mobile, automotive, and industrial devices. The issue involves a weakness in how the hardware protects sensitive encryption keys, which could allow an attacker with local access to the device to compromise secure data. This could lead to the exposure of private information or the unauthorized modification of secure system components.

Technical details

This vulnerability (CWE-323) stems from the reuse of a nonce or initialization vector (IV) during AES-GCM key wrapping. AES-GCM requires a unique IV for every encryption operation to maintain its security properties; using a static IV allows an attacker with local access to potentially perform cryptographic attacks to recover the wrapped keys. The issue affects a wide range of Snapdragon platforms including Mobile, Auto, and Compute. Users should apply firmware updates provided by their device manufacturers as referenced in the July 2026 Qualcomm Security Bulletin.

Affected products

  • Qualcomm, Inc. Snapdragon FastConnect 6900, FastConnect 7800, QCA6595AU, QCA6696, QDU1000, SA8255P, and others

Timeline

  • 2026-07-06: advisory: Initial publication of the Qualcomm security bulletin and NVD entry.

References

Related threats