Executive brief
A security vulnerability exists in Qualcomm chipsets during the early boot process. An attacker with physical access to a device and high-level privileges could use specific commands to cause memory corruption. This could allow them to bypass security protections, potentially leading to full control over the device's hardware and data.
Technical details
A memory corruption vulnerability exists in the Qualcomm bootloader (fastboot) component due to improper validation of syntactic correctness of input (CWE-1286). The flaw is triggered when processing specific fastboot commands used to set the display mode. An attacker with physical access and administrative/high privileges can exploit this to achieve arbitrary code execution or a permanent denial of service. The vulnerability is characterized by a CVSS 3.1 score of 7.2, with a scope change (S:C) indicating potential impact beyond the immediate boot environment. Fixes are typically distributed via OEM security updates.
Affected products
- Qualcomm Snapdragon Mobile
Timeline
- 2026-06-01: advisory: Qualcomm published the security bulletin and CVE details.