Executive brief
Qualcomm's fingerprint trusted application (TA) contains a memory corruption vulnerability when processing malformed request parameters. An attacker able to send crafted requests to the fingerprint service could trigger memory corruption, potentially leading to service crashes or unauthorized access to sensitive biometric data.
Technical details
A memory corruption vulnerability exists in Qualcomm's fingerprint trusted application when handling malformed request parameters. The vulnerability stems from insufficient validation of input parameters before processing them in memory operations. The fingerprint TA is a sensitive component handling biometric authentication; exploitation could occur from a local or adjacent network context with access to the vulnerable service. An attacker can cause memory corruption leading to denial of service or potential privilege escalation within the trusted execution environment. Patches are expected to be available through Qualcomm's security bulletins.
Affected products
- Qualcomm fingerprint TA <UNKNOWN>
Timeline
- 2026-08-04: disclosed