CVE-2026-21374

7.8

Qualcomm · Snapdragon (AQT1000, Cologne, FastConnect 6200, 6700, 6800, 6900, 7800, QCA0000)

A buffer over-read vulnerability in Qualcomm Snapdragon auxiliary sensor processing allows local attackers with low privileges to potentially trigger memory corruption.

Executive summary

A memory corruption vulnerability in various Qualcomm Snapdragon components poses a high risk of local system compromise and unauthorized data access.

Vulnerability

This flaw is a buffer over-read (CWE-126) occurring during the processing of auxiliary sensor input/output control commands. The vulnerability requires a local attacker with low privileges to interact with the affected driver or interface.

Business impact

The vulnerability carries a CVSS score of 7.8, which indicates a High severity level. Successful exploitation allows a local attacker to achieve total technical impact on the affected system, potentially leading to unauthorized data disclosure or service disruption. In a business context, this could result in the compromise of sensitive information stored on mobile or embedded devices, necessitating urgent remediation to prevent local privilege escalation.

Remediation

Immediate Action: Consult the official Qualcomm security bulletin for April 2026 to identify and apply the relevant firmware or driver updates for your specific device model.

Proactive Monitoring: Monitor system logs for unusual crashes or error messages related to sensor input/output operations, which may indicate attempted exploitation.

Compensating Controls: Ensure that device access controls remain strictly enforced to limit the capability of local users to interact with hardware interfaces directly.

Exploitation status

Public Exploit Available: No (exploit_available: unknown).

Analyst recommendation

Given the severity of this memory corruption vulnerability and its potential for total impact, administrators should prioritize the deployment of firmware updates provided by the device manufacturer. Always verify that updates are sourced directly from official vendor channels to ensure the integrity of the remediation.

More Qualcomm CVEs

Sources