Executive brief
A memory corruption vulnerability exists in several Qualcomm Snapdragon chipsets used in mobile devices, automotive systems, and IoT hardware. An attacker with local access to a device could exploit this flaw to interfere with the device's normal operations or potentially gain unauthorized access to sensitive data. This could lead to system instability or a compromise of the device's security boundaries.
Technical details
A memory corruption vulnerability (CWE-787: Out-of-bounds Write) exists in Qualcomm Snapdragon firmware. The issue occurs when updating prepared commands using invalid port indices provided by user-space input that exceeds supported read client limits. An attacker with low-privileged local access can trigger this vulnerability, though it requires high complexity to exploit successfully. If exploited, it can lead to a scope cross (S:C), potentially allowing the attacker to impact the integrity and availability of the underlying system or secure environments. Patch information is available in the July 2026 Qualcomm Security Bulletin.
Affected products
- Qualcomm, Inc. Snapdragon Auto
- Qualcomm, Inc. Snapdragon Compute
- Qualcomm, Inc. Snapdragon Consumer IOT
- Qualcomm, Inc. Snapdragon Industrial IOT
- Qualcomm, Inc. Snapdragon Mobile
- Qualcomm, Inc. FastConnect 6700
- Qualcomm, Inc. FastConnect 6900
- Qualcomm, Inc. FastConnect 7800
Timeline
- 2026-07-06: disclosed
- 2026-07-06: advisory