CVE-2026-24080

Qualcomm · Snapdragon

A buffer overflow vulnerability exists in the Qualcomm Snapdragon fingerprint Trusted Application, triggered by the handling of malformed request parameters.

Executive summary

A high severity buffer overflow vulnerability in the Qualcomm Snapdragon fingerprint Trusted Application could allow a local, low-privileged attacker to achieve unauthorized code execution.

Vulnerability

This is a buffer overflow vulnerability (CWE-120) involving the failure to validate the size of input parameters within the fingerprint Trusted Application. The attack requires the user to have local, low-privileged access to the device.

Business impact

With a CVSS score of 7.8, this vulnerability represents a serious threat to secure processing environments. If exploited, an attacker could gain control over the fingerprint authentication process, potentially leading to a total compromise of the security features managed by the Trusted Application.

Remediation

Immediate Action: Apply the latest security updates provided by the device manufacturer as detailed in the August 2026 Qualcomm security bulletin.

Proactive Monitoring: Review system and audit logs for anomalies related to the fingerprint authentication service or unexpected process terminations.

Compensating Controls: Restrict physical and local access to the device to prevent unauthorized individuals from executing the necessary commands to trigger the overflow.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability highlights the need for rigorous input validation within Trusted Execution Environments. Organizations should treat this as a high priority update, ensuring that patches are tested and deployed to all vulnerable hardware to prevent potential exploitation of the biometric authentication subsystem.