Executive brief
A security vulnerability exists in Qualcomm chipsets when processing command line display information. An attacker with physical access to a device and high-level privileges could exploit this flaw to corrupt system memory. This could lead to a complete compromise of the device's integrity and confidentiality, potentially allowing for unauthorized access to sensitive data or permanent device impairment.
Technical details
A stack-based buffer overflow (CWE-121) exists in Qualcomm firmware during the processing of display command line information. The root cause is the improper initialization of a variable, which leads to memory corruption. Exploitation requires physical access to the device (AV:P) and high privileges (PR:H). If successfully exploited, an attacker can achieve a scope jump (S:C) and gain full control over the confidentiality, integrity, and availability of the system. The vulnerability was disclosed in the June 2026 Qualcomm Security Bulletin.
Affected products
- Qualcomm Snapdragon Mobile
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory