CVE-2026-24080
Qualcomm · Snapdragon
A buffer overflow vulnerability exists in the Qualcomm Snapdragon fingerprint Trusted Application, triggered by the handling of malformed request parameters.
Executive summary
A high severity buffer overflow vulnerability in the Qualcomm Snapdragon fingerprint Trusted Application could allow a local, low-privileged attacker to achieve unauthorized code execution.
Vulnerability
This is a buffer overflow vulnerability (CWE-120) involving the failure to validate the size of input parameters within the fingerprint Trusted Application. The attack requires the user to have local, low-privileged access to the device.
Business impact
With a CVSS score of 7.8, this vulnerability represents a serious threat to secure processing environments. If exploited, an attacker could gain control over the fingerprint authentication process, potentially leading to a total compromise of the security features managed by the Trusted Application.
Remediation
Immediate Action: Apply the latest security updates provided by the device manufacturer as detailed in the August 2026 Qualcomm security bulletin.
Proactive Monitoring: Review system and audit logs for anomalies related to the fingerprint authentication service or unexpected process terminations.
Compensating Controls: Restrict physical and local access to the device to prevent unauthorized individuals from executing the necessary commands to trigger the overflow.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability highlights the need for rigorous input validation within Trusted Execution Environments. Organizations should treat this as a high priority update, ensuring that patches are tested and deployed to all vulnerable hardware to prevent potential exploitation of the biometric authentication subsystem.