Executive brief
A security vulnerability exists in several Qualcomm Snapdragon chipsets used in mobile, industrial, and computing devices. An attacker with local access to a device could exploit a timing issue during data processing to corrupt system memory. This could lead to a complete system crash or allow the attacker to gain unauthorized control over the device's functions and data.
Technical details
This vulnerability is a Time-of-Check Time-of-Use (TOCTOU) race condition (CWE-367) occurring within the firmware of various Qualcomm Snapdragon chipsets. The flaw exists in the handling of asynchronous input parameters where values are modified between the initial validation check and their subsequent use. A local attacker with low privileges can exploit this race condition to trigger memory corruption. Successful exploitation can lead to a loss of confidentiality, integrity, and availability, potentially allowing for arbitrary code execution at a high privilege level. The issue affects multiple platforms including Snapdragon Compute and Industrial IOT.
Affected products
- Qualcomm Snapdragon Cologne, FastConnect 6900, FastConnect 7800, IQX5121, IQX7181, QCA0000, SC8380XP, WCD9378C, WCD9380, WCD9385, WSA8840, WSA8845, WSA8845H, X2000077, X2000086, X2000090, X2000092, X2000094, XG101002, XG101032, XG101039
Timeline
- 2026-07-06: disclosed
- 2026-07-06: advisory: Qualcomm July 2026 Security Bulletin published