Kaspersky discovered a hardware vulnerability in Qualcomm Snapdragon chips

Kaspersky discovered a hardware vulnerability in Qualcomm Snapdragon chips

95 hardware

Kaspersky identified a hardware vulnerability in Qualcomm Snapdragon chipsets

At the Black Hat Asia 2026 conference, the “Kaspersky Lab” team presented research that discovered a critical flaw in the trusted boot chain of Qualcomm processors. The vulnerability allows an attacker with physical access to install backdoors into application kernels and fully control the system.

What was found
* Target – the Qualcomm Sahara protocol used when devices are switched to Emergency Download Mode (EDL).

This mode is used for repair and reflashing: it loads software before the OS starts.

* Problem – during EDL the trust chain is broken, opening a path to inject malicious code into the processor.

* Scope – seventeen series of chipsets:

* MDM9x07, MDM9x45, MDM9x65
* MSM8909, MSM8916, MSM8952
* SDX50

Additionally, the risk may extend to other vendors using similar platforms.

* Identifier – CVE‑2026‑25262. Qualcomm was notified of the issue in March last year and confirmed it in April.

How the attack works
1. Physical access – the attacker connects the device to their equipment via a cable.
2. On modern smartphones, the phone must be put into special EDL mode (often achievable with a button combination).
3. When connected to untrusted USB ports (charging stations at airports, hotels, etc.) the risk increases—even without manual intervention.

* Time – a few minutes are enough to inject malicious code.
* The threat is relevant not only during operation but also at repair or supply stages: the device may reach the user already compromised.

What attackers can gain
* Access to personal data, camera and microphone.
* In some scenarios full control over the device (including covert data collection).

Kaspersky expert Sergey Anufrienko noted: “Malware installed in this way is hard to detect and remove. It can run in the background for a long time, and the system sometimes simulates a reboot without actually shutting down. To ensure removal, you must completely cut power—e.g., wait for the battery to drain.”

Attack limitations
* Physical cable access makes the attack vector narrow: it’s about targeted operations, not mass infection via the internet.
* The vulnerability affects legacy chipsets, and most modern flagship smartphones remain out of range.

How to close the breach
Only Qualcomm or device manufacturers (Samsung, Xiaomi, etc.) can fully fix the issue by releasing a BootROM firmware update. Until such patches appear, users should limit physical access to their devices and avoid connecting to unknown USB ports.

Comments (0)

Share your thoughts — please be polite and stay on topic.

No comments yet. Leave a comment — share your opinion!

To leave a comment, please log in.

Log in to comment