Junglewise Threat Intelligence

CVE-2026-24089: Qualcomm Snapdragon memory corruption in fastboot command processing

CVE-2026-24089 · Severity: high · CVSS 7.2 · Published 2026-06-01

Technologies: Qualcomm Snapdragon Mobile. Vendors: Qualcomm.

Executive brief

A security vulnerability exists in the bootloader software of certain Qualcomm-based mobile devices. An attacker with physical access to the device and high-level privileges could use specially crafted commands to cause memory corruption. This could potentially allow the attacker to bypass security protections, gain unauthorized access to data, or disable the device.

Technical details

A memory corruption vulnerability exists in the Qualcomm fastboot implementation due to improper validation of syntactic correctness of input (CWE-1286). The flaw is triggered when the bootloader processes malformed fastboot commands. An attacker requires physical access to the device (AV:P) and high privileges (PR:H) to execute the exploit. Successful exploitation can lead to a scope change (S:C), potentially allowing for arbitrary code execution at the bootloader level, impacting the confidentiality, integrity, and availability of the entire system. Fixes are typically distributed via OEM security updates.

Affected products

  • Qualcomm Snapdragon Mobile

Timeline

  • 2026-06-01: disclosed: Initial publication by Qualcomm and NVD

References

Related threats