Executive brief
A security vulnerability exists in Qualcomm's Strongbox, a hardware-backed security component used to protect sensitive cryptographic keys and data on mobile devices. An attacker with local access to the device could exploit this flaw to corrupt system memory, potentially bypassing security protections. This could lead to the unauthorized access of protected information or a complete compromise of the device's secure environment.
Technical details
A memory corruption vulnerability exists in the Qualcomm Strongbox component due to improper validation of array indexes (CWE-129). The flaw is rooted in a missing bounds check during data processing within the secure environment. A local attacker with low privileges can exploit this vulnerability to trigger memory corruption. Because the vulnerability involves a 'Scope Change' (S:C) in the CVSS metric, an exploit could allow an attacker to break out of the restricted Strongbox environment and impact the underlying secure processor or host system, leading to a full loss of confidentiality, integrity, and availability.
Affected products
- Qualcomm Strongbox
Timeline
- 2026-06-01: advisory: Qualcomm published the security bulletin and the CVE was added to the NVD.