Junglewise Threat Intelligence

CVE-2026-21384: Qualcomm Snapdragon Memory Corruption in Prepared Commands

CVE-2026-21384 · Severity: medium · CVSS 5.3 · Published 2026-07-06

Technologies: Qualcomm, Inc. Snapdragon Compute, Qualcomm, Inc. Fastconnect 6700, Qualcomm, Inc. Snapdragon Auto, Qualcomm, Inc. Fastconnect 6900, Qualcomm, Inc. Snapdragon Industrial IOT, Qualcomm, Inc. Fastconnect 7800, Qualcomm, Inc. Snapdragon Mobile, Qualcomm, Inc. Snapdragon Consumer IOT.

Executive brief

A memory corruption vulnerability exists in several Qualcomm Snapdragon chipsets used in mobile devices, automotive systems, and IoT hardware. An attacker with local access to a device could exploit this flaw to interfere with the device's normal operations or potentially gain unauthorized access to sensitive data. This could lead to system instability or a compromise of the device's security boundaries.

Technical details

A memory corruption vulnerability (CWE-787: Out-of-bounds Write) exists in Qualcomm Snapdragon firmware. The issue occurs when updating prepared commands using invalid port indices provided by user-space input that exceeds supported read client limits. An attacker with low-privileged local access can trigger this vulnerability, though it requires high complexity to exploit successfully. If exploited, it can lead to a scope cross (S:C), potentially allowing the attacker to impact the integrity and availability of the underlying system or secure environments. Patch information is available in the July 2026 Qualcomm Security Bulletin.

Affected products

  • Qualcomm, Inc. Snapdragon Auto
  • Qualcomm, Inc. Snapdragon Compute
  • Qualcomm, Inc. Snapdragon Consumer IOT
  • Qualcomm, Inc. Snapdragon Industrial IOT
  • Qualcomm, Inc. Snapdragon Mobile
  • Qualcomm, Inc. FastConnect 6700
  • Qualcomm, Inc. FastConnect 6900
  • Qualcomm, Inc. FastConnect 7800

Timeline

  • 2026-07-06: disclosed
  • 2026-07-06: advisory

References