الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Kaspersky discovers vulnerability in Qualcomm Snapdragon chips that can lead to data loss & device compromise

Kaspersky ICS CERT discovered a hardware-level vulnerability affecting Qualcomm chipsets that are widely used in a range of consumer and industrial devices, including smartphones and tablets, car components, IoT devices and more. The vulnerability resides in the BootROM – firmware embedded at the hardware level. Attackers could potentially get access to any data stored on the device or device sensors like camera and microphone, implement complicated attack scenarios and in some circumstances get full control of the device. The results of the research were presented at Black Hat Asia 2026.
The vulnerability affects Qualcomm MDM9x07, MDM9x45, MDM9x65, MSM8909, MSM8916, MSM8952 and SDX50 series and was reported to Qualcomm in March 2025. Qualcomm formally acknowledged the vulnerability in April 2025. It has been assigned a CVE-2026-25262. Other Qualcomm-based chips may be affected as well.
Kaspersky researchers explored the Sahara protocol, a low-level communication system used when a Qualcomm chip enters Emergency Download Mode (EDL) – a special recovery mode designed for repairing or restoring smartphones or other devices. Sahara acts as the first step that allows a computer to connect to the device and load software before the operating system on the device starts.
Kaspersky demonstrated that a security flaw in this process could allow an attacker with physical access to the target device to bypass key security protections in the chip, compromise the secure boot chain and, in some cases, deploy malicious applications and backdoors to the chip’s Application Processor, thus fully compromising the entire device. For example, in cases when the target device is a smartphone or a tablet, the attacker can potentially get access to entered user passwords, and subsequently this opens further access to multiple types of sensitive user data, such as files, contacts, location, access to the devices’ camera and microphone, etc.
A potential attacker only needs a few minutes of physical access to a device to compromise it. Therefore, if a smartphone has been sent for repair or left unattended for a short time, one can no longer be sure it is not infected. Researchers warn that the threat extends beyond end-user scenarios to include potential compromise during the supply chain phase.
“Vulnerabilities like this may allow attackers to deploy malware that is difficult to detect and remove. In practice, this could enable covert data collection or influence device behavior over extended periods of time. While a reboot might seem like an effective way to remove such malware, it cannot always be relied upon: compromised systems may simulate a reboot without actually resetting. In such cases, only a complete loss of power – including battery depletion – guarantees a clean restart,” comments Sergey Anufrienko, security expert at Kaspersky ICS CERT.
Kaspersky advises organizations and individual users to exercise strict physical security control over devices including at the supply, maintenance and decommissioning phases. A reboot of the device by cutting off the power supply to the affected chip (if available) or full battery discharge may help to get rid of the malware if it was installed.
Read the advisory on the website of Kaspersky ICS CERT.

Related Posts:

Madinet Masr Awards EGP 1.38 Billion for Origami at Taj City

إدراج 47 جامعة مصرية في تصنيف UI GreenMetric للاستدامة لعام 2026

حجر أساس لمشروع أعلاف باستثمارات صينية.. والزراعة تؤكد دعم الشراكة مع القطاع الخاص

Zoho Launches Agent-Ready Catalyst Platform for AI App Development

Turkish Airlines Named Europe’s Best Airline for the 11th Time

NILEWOOD Expands in Saudi Arabia at Saudi Wood Show 2026

Turkish Airlines and Air China Expand Codeshare Agreement

PATRIZIA appoints Hassan Awada as Senior Executive Officer to lead and accelerate Middle East expansion

آخر الأخبار
مصر تدين اقتحام المستوطنين الإسرائيليين للمسجد الأقصى المبارك بنك القاهرة وشركة فيزا يوقعان اتفاقية تعاون لدعم تطوير حلول ومنتجات دفع جديدة محافظ البنك المركزي ووزير الصناعة يطلقان صندوق إعادة هيكلة المصانع المتعثرة برأسمال مليار جنيه إف سي بايرن ميونخ يؤسس أكاديمية تعمل على مدار العام في الشرق الأوسط، ويقدّم نموذجه المتميز لتطوير ال... دولة الإمارات تجدد التزامها بالتنمية المستدامة خلال الاجتماع السنوي لمجلس محافظي البنك الآسيوي للاس... المكتب الطبي يعلن حصول «مستشفيات الشيخ خليفة» على اعتماد «مسار التميّز بامتياز» من «المركز الأمريكي ... مجموعة دلسكو تطلق برنامج «خطوة» للمواهب الوطنية لتطوير وتمكين الكفاءات الإماراتية شراكة بين "عزيزي" و"كوني" لتطوير أنظمة النقل العمودي في "برج عزيزي" أومودا وجايكو تستعد للكشف العالمي عن ‎OMODA X‎ وتقنيات هجينة وذكية جديدة في الصين مجلس الوزراء: تخصيص 150 فدانًا لـ "قصر العيني" في أكتوبر لا يعني التخلي عن موقعه التاريخي شركة «Rock Developments» تعزز ثقة عملائها وتحتفي بشركاء النجاح خلال «ROCK EXPO II» "مدن" تطلق المرحلة الأولى من مشروع "وديم غاردنز" أول مجمتع سكني في أبوظبي يتيح خيار الشراء بتمويل من... الاتحاد المصري لتمويل المشروعات يختتم اعمال المؤتمر العالمي لـ Cerise+SPTF 2026 بمشاركة دولية رئيس البورصة المصرية يستعرض تطورات السوق وفرص جذب الاستثمارات الأجنبية خلال مؤتمر «MEIRA» بدبي أوهانا للتطوير العقاري تطلق برنامجاً لتمكين الوسطاء العقاريين الإماراتيين خلال "ليفكس 2026" بنك ناصر الاجتماعي يطرح شهادة «رد الجميل» بعوائد مميزة بمناسبة اليوم العالمي للمسنين Workday تطلق أعمالها في الإمارات لدعم تحول المؤسسات في مجالات الموارد البشرية في عصر الذكاء الاصطناع... نيميتشك وتحالف البناء الأخضر السعودي يتعاونان لدعم البناء المستدام والرقمي في المملكة صندوق استثماري جديد بقيادة إكساب لدعم النمو وتمويل المشروعات في شمال أمريكا اللاتينية تفاصيل اجتماع الرئيس السيسى لمناقشة خطط التوسع الصناعى وتعميق التصنيع المحلى