Executive brief
A security vulnerability in Qualcomm chipsets could allow an attacker with local access to bypass secure boot protections. By exploiting a flaw in how the device processes partition tables, an attacker could modify the startup process to run unauthorized software. This could lead to a total compromise of the device's integrity and the exposure of sensitive user data.
Technical details
A cryptographic vulnerability exists in Qualcomm firmware due to missing authentication for a critical function (CWE-306) during the processing of partition table entries. An attacker with local access and low privileges can exploit this flaw to bypass secure boot mechanisms and modify the boot flow. This allows for the execution of unsigned or malicious code early in the boot process, potentially leading to persistent device compromise. The vulnerability was disclosed in the June 2026 Qualcomm security bulletin.
Affected products
- Qualcomm Snapdragon Mobile
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory: Published in Qualcomm June 2026 Security Bulletin