CVE-2026-21371

7.8

Qualcomm · Snapdragon

A buffer over-read vulnerability in Qualcomm Snapdragon components allows for potential memory corruption due to insufficient size validation during output buffer retrieval.

Executive summary

A memory corruption vulnerability in various Qualcomm Snapdragon products poses a high risk of system compromise and denial of service.

Vulnerability

This vulnerability is a buffer over-read (CWE-126) triggered during the retrieval of an output buffer, where the system fails to perform adequate size validation. The attack vector is local, requiring low privileges to execute.

Business impact

Successful exploitation of this memory corruption flaw can lead to unauthorized information disclosure, data integrity compromise, or system instability. With a CVSS score of 7.8, the vulnerability is classified as High severity, indicating a significant risk to the confidentiality, integrity, and availability of the affected mobile and connectivity hardware.

Remediation

Immediate Action: Review the April 2026 Qualcomm Security Bulletin and apply the recommended firmware updates provided by your device manufacturer.

Proactive Monitoring: Monitor system logs for unusual crash patterns or unexpected service restarts that may indicate memory corruption attempts.

Compensating Controls: Ensure that device security features, such as hardware backed keystores and kernel integrity protection, are fully enabled to limit the potential impact of local exploitation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the High severity of this flaw, security teams should prioritize the deployment of vendor-supplied firmware updates as soon as they become available for the specific Snapdragon hardware in their fleet. Organizations should coordinate with their device vendors to ensure these security patches are validated and distributed to end users to prevent potential local exploitation.

More Qualcomm CVEs

Sources