LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-11261: Qualcomm Multiple Chipsets Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 1, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 1, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-11261 to its Known Exploited Vulnerabilities catalog on Dec 1, 2021, with a federal patch deadline of Jun 1, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon…

CVE-2020-11261 is an improper input validation flaw in multiple Qualcomm Snapdragon chipset families that can lead to memory corruption. It matters because the affected platforms appear widely in mobile devices, IoT, automotive, compute, and wearable systems; a successful attack could compromise device integrity or allow further privilege abuse on systems that rely on these chipsets.

Public detail is limited to the CISA description of memory corruption from a missing error check on oversized memory-allocation requests by a user application. Confirm exact impact, affected firmware builds, and exploitation prerequisites against the vendor advisory before prioritizing response.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). In this case, the chipset software does not properly validate or reject a user-application request for an extremely large memory allocation and fails to return an error as expected. That missing check can result in memory corruption.

An attacker who can run or influence a user-level application on a device containing an affected Snapdragon component could attempt to trigger the oversized allocation path. Beyond that high-level description, specific exploit mechanics, required privileges, or reliable exploitation steps are not provided in the available facts; treat any public proof-of-concept claims with caution and verify them against the vendor advisory.

Am I affected? How to find it in your systems

Affected product lines listed by CISA are Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, and Snapdragon Wearables. These chipsets commonly appear in smartphones, tablets, embedded industrial and consumer IoT devices, automotive head units or telematics, wearables, and certain compute modules.

How to remediate

The required action is to apply updates per vendor instructions. Obtain and deploy the security patches or firmware updates that Qualcomm and the device OEM have issued for CVE-2020-11261.

If you can't patch immediately

When immediate firmware updates are not feasible, reduce exposure with compensating controls while you schedule the vendor fix.

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and subsequent data exposure, although ransomware use is not documented for this CVE. If you suspect exploitation, isolate the device, preserve logs and memory images where feasible, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data sets to check whether associated credentials or personal information have already appeared in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQualcomm · Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
WeaknessCWE-20
Added to CISA KEVDec 1, 2021
Federal patch deadlineJun 1, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities