CVE-2020-11261
KEVmassLocal Privilege Escalation via Memory Corruption in Qualcomm Snapdragon Chipsets
CISA: Qualcomm Multiple Chipsets Improper Input Validation Vulnerability
CVE-2020-11261 is an improper input validation flaw (CWE-20/CWE-787, resulting in memory corruption/out-of-bounds writes) in the memory-allocation handling of firmware across a wide range of Qualcomm Snapdragon chipsets. It is triggered when a user application requests a memory allocation of a huge size and the affected component fails to properly return an error; a local attacker — such as a malicious or compromised app already running on the device — can leverage this to escalate privileges. Successful exploitation yields elevated privileges with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, local attack vector, no user interaction required). Affected platforms span the Snapdragon Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, Voice & Music, and Wearables product lines, including widely deployed entry-level mobile SoCs and connectivity chips. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-12-01, confirming in-the-wild exploitation; it was quietly patched in Android security updates alongside related Arm and Qualcomm zero-days, no public PoC is known, and EPSS estimates a 1.8% probability of exploitation in the next 30 days.
What to do: Apply updated Qualcomm firmware and driver packages per the vendor advisory, as required by CISA's KEV listing, and ensure Android devices receive the OEM security updates containing the fix. Inventory devices built on the listed chipsets (e.g., APQ8009, APQ8017, APQ8053, APQ8096AU) and confirm they run patched builds; there is no workaround beyond patching, since a local malicious app is sufficient to trigger the flaw.
| Qualcomm APQ8009 firmware | — |
| Qualcomm APQ8009W firmware | — |
| Qualcomm APQ8017 firmware | — |
| Qualcomm APQ8037 firmware | — |
| Qualcomm APQ8053 firmware | — |
| Qualcomm APQ8064AU firmware | — |
| Qualcomm APQ8096AU firmware | — |
| Qualcomm AQT1000 firmware | — |
| Qualcomm AR8031 firmware | — |
| Qualcomm AR8035 firmware | — |
| Qualcomm AR8151 firmware | — |
| Qualcomm CSRA6620 firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- Affected
- Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- qualcomm
- Products
- apq8009 firmware, apq8009w firmware, apq8017 firmware, apq8037 firmware, apq8053 firmware, apq8064au firmware, apq8096au firmware, aqt1000 firmware, ar8031 firmware, ar8035 firmware, ar8151 firmware, csra6620 firmware
- Weakness
- CWE-787, CWE-20
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H