Executive brief
A security vulnerability exists in the bootloader software of Qualcomm-based mobile devices. This component is responsible for starting the device's operating system and managing low-level hardware commands. If an attacker has physical access to the device and administrative privileges, they could potentially corrupt the system's memory, leading to a complete compromise of the device's security and data.
Technical details
A memory corruption vulnerability exists in the Qualcomm bootloader during the processing of fastboot OEM commands. The issue is categorized as CWE-1286 (Improper Validation of Syntactic Correctness of Input), where the system fails to properly validate input before processing. An attacker with physical access to the device and high privileges (PR:H) can exploit this flaw to achieve arbitrary code execution or a system-wide compromise (Scope: Changed). The vulnerability was disclosed in the June 2026 Qualcomm Security Bulletin.
Affected products
- Qualcomm Snapdragon Mobile Platforms
Timeline
- 2026-06-01: disclosed: Initial publication of the CVE and Qualcomm security bulletin.