Executive brief
A security vulnerability exists in the bootloader software of certain Qualcomm-based mobile devices. An attacker with physical access to the device and high-level privileges could use specially crafted commands to cause memory corruption. This could potentially allow the attacker to bypass security protections, gain unauthorized access to data, or disable the device.
Technical details
A memory corruption vulnerability exists in the Qualcomm fastboot implementation due to improper validation of syntactic correctness of input (CWE-1286). The flaw is triggered when the bootloader processes malformed fastboot commands. An attacker requires physical access to the device (AV:P) and high privileges (PR:H) to execute the exploit. Successful exploitation can lead to a scope change (S:C), potentially allowing for arbitrary code execution at the bootloader level, impacting the confidentiality, integrity, and availability of the entire system. Fixes are typically distributed via OEM security updates.
Affected products
- Qualcomm Snapdragon Mobile
Timeline
- 2026-06-01: disclosed: Initial publication by Qualcomm and NVD