Qualcomm Patches Critical Security Flaw That Affects 46 Chipsets, but Millions of Devices Still Vulnerable

Advertisement
By Harpreet Singh | Updated: 26 April 2019 17:16 IST
Highlights
  • Qualcomm's chipsets had a security vulnerability which has been patched
  • 46 Qualcomm chipsets were affected due to the security flaw
  • Android April 2019 security update includes a fix for the flaw

Qualcomm has issued firmware patches earlier this month, but millions of devices are still vulnerable

Qualcomm chipsets are used in a wide range of smartphones, tablets, and other devices. The company's chipsets power millions of devices across the world. But even the most powerful chipsets can be prone to flaws. A new vulnerability has been discovered in Qualcomm's chipsets that could allow an attacker to gain root access on the device. The flaw affects 46 Qualcomm chipsets which are currently used in several smartphones, tablets, laptops, and smartwatches.

The security bug (CVE-2018-11976) can enable an attacker to gain access to private data and even encryption keys stored in the Qualcomm Secure Execution Environment (QSEE). Qualcomm has patched the flaw earlier this month, tagging it as 'critical'.

The flaw was first discovered in March last year by Keegan Ryan, a security researcher with NCC Group, as reported by ZDNet. Ryan has also published a white paper, explaining the flaw. He claims he was able to grab private security keys using a rooted Nexus 5X smartphone.

Advertisement

Google has added the fix as a part of its April 2019 security patches, but Android manufacturers are known to be lazy about pushing security patches to its consumers. This means a large number of Android devices using these Qualcomm chipsets are still prone to the security vulnerability.

Advertisement

The Qualcomm Security Executive Environment (QSEE) offers a safe environment to process critical data including private encryption keys and passwords. Only the app that stored the data in QSEE can access it, preventing malicious apps from accessing the sensitive data.

QSEE was created to prevent anyone from gaining complete access to a device, but the latest security flaw defeats that purpose entirely. To exploit the vulnerability, an attacker needs root access on a device which isn't quite impossible.

Advertisement

The flaw affects popular Qualcomm chips used on smartphones such as: Snapdragon 200 series, Snapdragon 400 series, Snapdragon 625, Snapdragon 660, Snapdragon 670, Snapdragon 710, Snapdragon 820, Snapdragon 835, and Snapdragon 845. Qualcomm has listed all the affected chipsets in its security bulletin.

Ryan said he has notified Qualcomm about the flaw last year. Earlier this month, Qualcomm had patched the vulnerability and it's now up to device manufacturers to quickly deploy Google's Android April 2019 security update.

Advertisement

In case you own a device that uses any of these 46 affected Qualcomm chips, make sure you upgrade to the Android April 2019 security patch as soon as it's made available by your phone's manufacturer.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Qualcomm, Snapdragon, Android
Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 15 Series India Launch Date, Price Range Leaked
  2. Inside the OPPO Find X9 Series: A Smarter Approach to Battery Life
  3. Realme 16 Pro Series Camera Details and Realme Buds Air Launch Date Revealed
  4. Xiaomi 17 Ultra, Poco X8 Pro Spotted on IMDA Ahead of Global Launch
  5. Paramount's New Offer for Warner Bros. Is Not Sufficient, Major Investor Says
  6. Shine On Me Now Streaming Online: Know Everything About Plot, Cast, and More
  7. Battle of the Nerds: Godfather of AI, Google DeepMind Chief Argue Over AGI
  8. Clair Obscur: Expedition 33 Loses Indie Game Awards Honour Over Gen AI Use
  9. ChatGPT Might Soon Support Skills, Make It Easy to Program Repeat Tasks
  10. Motorola Edge 70 Goes on Sale in India: See Price, Offers, Features
  1. Realme Pad 3 Key Specifications Tipped Ahead of India Launch; to Feature 2.8K Display and 45W Wired Charging
  2. NASA’s SPHEREx Telescope Delivers First Full-Sky Map, Unlocking Cosmic Secrets
  3. Robotic Arm Achieves 1,000 Tasks in a Day Through Innovative Imitation Learning
  4. Ponies OTT Release Date: Know When to Watch This Emilia Clarke and Haley Lu Richardson starrer web series online
  5. Bhabhi Ji Ghar Par Hain 2.0 Now Streaming Online: What You Need to Know
  6. Paramount's New Offer for Warner Bros. Is Not Sufficient, Major Investor Says
  7. HMD Pulse 2 Specifications Leaked; Could Launch With 6.7-Inch Display, 5,000mAh Battery
  8. WhatsApp Begins Testing Support for Viewing Connected Peripherals
  9. OpenAI Tipped to Add Skills Feature to ChatGPT, Could Be Available as Slash Commands
  10. Is AGI Possible? Godfather of AI and Google DeepMind Chief Caught in War of Words on Social Media
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.