Junglewise Threat Intelligence

CVE-2026-24091: Qualcomm Snapdragon memory corruption in fastboot commands

CVE-2026-24091 · Severity: high · CVSS 7.2 · Published 2026-06-01

Technologies: Qualcomm Snapdragon Mobile. Vendors: Qualcomm.

Executive brief

A security vulnerability exists in the fastboot interface of Qualcomm chipsets, which are used to manage device firmware and recovery. An attacker with physical access to a device and high-level privileges could use specially crafted commands to cause memory corruption. This could allow the attacker to bypass security boundaries, potentially leading to full device compromise or permanent loss of data availability.

Technical details

A memory corruption vulnerability exists in the Qualcomm fastboot implementation due to improper validation of syntactic correctness of input (CWE-1286). The flaw is triggered when the bootloader processes improperly formatted fastboot commands. An attacker with physical access and administrative/high privileges can exploit this to achieve a scope change, potentially gaining unauthorized access to secure memory regions or executing arbitrary code at the bootloader level. The vulnerability is tracked as CVE-2026-24091 and was addressed in the June 2026 Qualcomm security bulletin.

Affected products

  • Qualcomm Snapdragon Mobile

Timeline

  • 2026-06-01: advisory: Qualcomm published the security bulletin and CVE details.

References

Related threats