CVE-2026-21376

7.8

Qualcomm · Snapdragon

A buffer over-read vulnerability in the camera sensor driver of various Qualcomm Snapdragon components allows for potential memory corruption via unvalidated IOCTL processing.

Executive summary

A memory corruption vulnerability in Qualcomm Snapdragon drivers poses a high risk of local privilege escalation or system instability.

Vulnerability

This is a buffer over-read (CWE-126) occurring during IOCTL processing. An authenticated local attacker with low privileges can trigger this flaw to achieve significant impact on system confidentiality, integrity, and availability.

Business impact

Successful exploitation of this vulnerability could lead to unauthorized access to sensitive data or complete system compromise. With a CVSS score of 7.8, this flaw represents a significant risk to organizational assets, particularly in mobile or embedded device environments where data privacy is critical.

Remediation

Immediate Action: Consult the Qualcomm security bulletin for April 2026 to identify specific firmware or driver updates for the affected Snapdragon components.

Proactive Monitoring: Monitor device logs for unusual driver crashes or unexpected system reboots, which may indicate attempted exploitation of IOCTL interfaces.

Compensating Controls: Ensure that device-level security policies restrict the execution of untrusted code to limit the ability of low-privileged users to interact with sensitive driver interfaces.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the severity of this memory corruption flaw, it is imperative that organizations managing devices utilizing the affected Qualcomm components prioritize the application of vendor-supplied patches. Security teams should monitor the official Qualcomm security bulletin for the release of specific firmware fixes and deploy them across the fleet as soon as they become available.

More Qualcomm CVEs

Sources