Junglewise Threat Intelligence

CVE-2026-24087: Qualcomm Snapdragon memory corruption in fastboot OEM commands

CVE-2026-24087 · Severity: high · CVSS 7.2 · Published 2026-06-01

Vendors: Qualcomm.

Executive brief

A security vulnerability exists in the bootloader software of Qualcomm-based mobile devices. This component is responsible for starting the device's operating system and managing low-level hardware commands. If an attacker has physical access to the device and administrative privileges, they could potentially corrupt the system's memory, leading to a complete compromise of the device's security and data.

Technical details

A memory corruption vulnerability exists in the Qualcomm bootloader during the processing of fastboot OEM commands. The issue is categorized as CWE-1286 (Improper Validation of Syntactic Correctness of Input), where the system fails to properly validate input before processing. An attacker with physical access to the device and high privileges (PR:H) can exploit this flaw to achieve arbitrary code execution or a system-wide compromise (Scope: Changed). The vulnerability was disclosed in the June 2026 Qualcomm Security Bulletin.

Affected products

  • Qualcomm Snapdragon Mobile Platforms

Timeline

  • 2026-06-01: disclosed: Initial publication of the CVE and Qualcomm security bulletin.

References