CVE-2026-21373

7.8

Qualcomm · Snapdragon (AQT1000, Cologne, FastConnect 6200, 6700, 6800, 6900, 7800, QCA0000)

A memory corruption vulnerability exists in multiple Qualcomm Snapdragon components due to improper buffer size validation during IOCTL processing.

Executive summary

A memory corruption vulnerability in various Qualcomm Snapdragon products could allow a local attacker with low privileges to execute arbitrary code or cause system instability.

Vulnerability

This is a buffer over-read (CWE-126) vulnerability triggered during IOCTL processing. An attacker with local access and low privileges can exploit this flaw by providing malicious input to the driver, leading to memory corruption.

Business impact

Successful exploitation of this vulnerability can lead to full system compromise, including unauthorized data access and denial of service. With a CVSS score of 7.8, the vulnerability is classified as High, reflecting the potential for significant impact on system integrity and availability, particularly in mobile and embedded environments where these chipsets are deployed.

Remediation

Immediate Action: Review the official April 2026 Qualcomm security bulletin and apply the specific vendor firmware or driver updates provided for your device model.

Proactive Monitoring: Monitor system logs for unusual kernel activity or unexpected system restarts that may indicate attempted memory corruption or crash scenarios.

Compensating Controls: Ensure that device security policies restrict local access to sensitive interfaces and maintain updated platform security patches to minimize the attack surface available to local users.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of memory corruption vulnerabilities in hardware drivers, IT administrators and device manufacturers must prioritize the deployment of the vendor-supplied patches. While the attack vector requires local access, the potential for high impact necessitates prompt action to ensure the security of the underlying hardware platform.

More Qualcomm CVEs

Sources