Qualcomm MSM Vulnerability That Could Give Access to SMS, Conversations, More Revealed; Fixes Reportedly Shared With OEMs

Qualcomm said in a statement that fixes were shared with OEMs in December 2020.

Advertisement
By Vineet Washington | Updated: 7 May 2021 13:53 IST
Highlights
  • Qualcomm has reportedly issues fixes for the vulnerability
  • It is unclear which phones have been fixed
  • Qualcomm MSM vulnerability could have allowed access to SMS, calls, etc

Qualcomm MSM supports advanced features like 5G, 4G LTE, and more

Photo Credit: Check Point Research

Qualcomm's Mobile Station Modems (MSM) had a vulnerability that could have allowed attackers to access a user's SMS, audio of phone conversations, and more. The vulnerability was discovered by research firm Check Point Research and it found over 400 vulnerabilities on Qualcomm's Snapdragon Digital Signal Processor (DSP) chip in August last year. With a vast number of Android phones using Qualcomm SoCs, this would have put a mind boggling number of users' data at risk. Qualcomm has reportedly released a patch, and Check Point Research also worked with relevant government officials as well as mobile vendors to make smartphones safer.

MSM, Check Point Research explains in a blog post, is a series of chips embedded in mobile devices and supports advanced features like 5G, 4G LTE, as well as high definition recording. It has been present in high-end phones since early 1990s. Android phones have a proprietary protocol called Qualcomm MSM Interface (QMI) that allows software components in the MSM to communicate with the cameras, fingerprint scanners, and other subsystems. Check Point Research found a vulnerability that could allow attackers to control the modem and inject malicious code into the modem from Android devices.

This would give attackers access to the user's call history and SMS records, as well as the ability to listen in on the user's conversations. It can also be used to unlock the SIM and bypass the limitations set by service providers. Check Point Research says that according to Counterpoint, QMI is present on around 30 percent of all mobile phones in the world. The vulnerability has been detailed in Check Point's blog.

Advertisement

The vulnerability was discolored to Qualcomm by Check Point Research and was classified as a high-rated vulnerability — CVE-2020-11292. Relevant mobile vendors were informed as well. According to a report by Arstechnica, a Check Point spokesman said that Qualcomm has released a patch for the vulnerability. However, it is unclear whether vulnerable Android devices have been fixed. Qualcomm reportedly said in a statement that fixes were made available to OEMs in December 2020 and consumers are recommended to update their devices as patches become available.

Advertisement

Check Point also recommends users update their devices to the latest version of the OS, refrain from installing apps from third party stores, and enable ‘remote wipe' capability on all mobile devices.


Is Mi 11X the best phone under Rs. 35,000? We discussed this on Orbital, the Gadgets 360 podcast. Later (starting at 23:50), we jump over to the Marvel series The Falcon and the Winter Soldier. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme P4 Power 5G With 10,001mAh Battery Arrives in India: See Price
  2. NASA's TESS Captures First Images of Rare Interstellar Comet 3I/ATLAS
  3. CERN Experiments Confirm Early Universe Behaved Like a Near-Perfect Fluid
  4. Daredevil: Born Again Season 2 OTT Release Date Confirmed: When and Where to Watch it Onli
  5. Champion OTT Release: Where To Watch Roshan Meka's Telugu Sports Drama Online?
  6. Adobe Express Premium Is Now Free for One Year for All Airtel Users
  7. Red Magic 11 Air Launched in Global Markets With ICE Cooling System
  8. Redmi Buds 8 Pro Launched With ANC, Hi-Res Audio at This Price
  9. Redmi Turbo 5 Max Launched With 9,000mAh Battery, Redmi Turbo 5 Tags Along
  10. Realme P4 Power 5G First Impressions
  1. CERN Experiments Confirm Early Universe Behaved Like a Near-Perfect Fluid
  2. NASA’s TESS Captures First Images of Rare Interstellar Comet 3I/ATLAS
  3. Daredevil: Born Again Season 2 OTT Release Date Confirmed: When and Where to Watch it Online?
  4. The Wrecking Crew Starring Jason Momoa and Dave Bautista Now Streaming: What You Need to Know
  5. Redmi Buds 8 Pro Launched With ANC, Hi-Res Audio and Up to 36 Hours of Total Battery Life
  6. Samsung Galaxy Tab S12+ Surfaces on IMEI Database, Could Launch Soon
  7. Champion OTT Release: Where To Watch Roshan Meka’s Telugu Sports Drama Online?
  8. Nothing Won't Launch a Flagship Model in 2026; Company to Focus on Nothing Phone 4a and Audio Products, Carl Pei Says
  9. Redmi Turbo 5 Max Launched With 9,000mAh Battery, Redmi Turbo 5 Tags Along: Price, Specifications
  10. Ponies Starring Emilia Clarke and Haley Lu Richardson Now Available for Streaming
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.