Executive brief
A security flaw exists in several Qualcomm Snapdragon chipsets used in mobile, automotive, and industrial devices. The issue involves a weakness in how the hardware protects sensitive encryption keys, which could allow an attacker with local access to the device to compromise secure data. This could lead to the exposure of private information or the unauthorized modification of secure system components.
Technical details
This vulnerability (CWE-323) stems from the reuse of a nonce or initialization vector (IV) during AES-GCM key wrapping. AES-GCM requires a unique IV for every encryption operation to maintain its security properties; using a static IV allows an attacker with local access to potentially perform cryptographic attacks to recover the wrapped keys. The issue affects a wide range of Snapdragon platforms including Mobile, Auto, and Compute. Users should apply firmware updates provided by their device manufacturers as referenced in the July 2026 Qualcomm Security Bulletin.
Affected products
- Qualcomm, Inc. Snapdragon FastConnect 6900, FastConnect 7800, QCA6595AU, QCA6696, QDU1000, SA8255P, and others
Timeline
- 2026-07-06: advisory: Initial publication of the Qualcomm security bulletin and NVD entry.