Skip to content
Droid ToolsDroid Tools
Home
About UsContact
Editorial PolicyReview Policy
Privacy PolicyCookie PolicyTerms & Conditions
⌘K
Search
FacebookX (Twitter)InstagramThreadsBlueskyTikTokYouTubeRedditTelegramRSS Feed
Droid Tools

Droid Tools covers the latest Android news, device reviews, app updates, and OS guides. Stay informed with hands-on coverage from mobile tech experts.

Explore

  • News
  • Apps
  • OS
  • Phones
  • Reviews

Legal & Info

  • About Us
  • Contact
  • Editorial Policy
  • Review Policy
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Affiliate Disclosure
  • Disclaimer
  • HTML Sitemap
  • XML Sitemap
© 2026 Droid Tools. All rights reserved.
Home/OS/Critical Snapdragon Exploit Takes Over Devices in Just 5 Minutes – What You Need to Know
OS
xiaomi

Critical Snapdragon Exploit Takes Over Devices in Just 5 Minutes – What You Need to Know

Kaspersky ICS CERT has publicly detailed a critical hardware vulnerability hitting a wide array of Qualcomm Snapdragon chipsets. The exploit, presented at Black Hat Asia 2026 on April 23 and tracked as CVE-2026-25262, has rattled the security community. First confirmed by Qualcomm in April 2025, full technical details are now available, exposing a backdoor capable …

Cristian Penisoara
Apr 26, 20262 min read
Cristian Penisoara
Cristian Penisoara
Guides Writer · Android Power User
Cristian Penisoara is a Guides Writer and Android specialist at Droid Tools. An Android user since version 2 and a professional event photographer, he combines technical curiosity with a detail-oriented approach - every guide he publishes is tested step-by-step on a real device before it goes live.
Profile →
snapdragon exploit
0%
Share on XFacebookBluesky
Follow on Google
Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source

Kaspersky ICS CERT has publicly detailed a critical hardware vulnerability hitting a wide array of Qualcomm Snapdragon chipsets. The exploit, presented at Black Hat Asia 2026 on April 23 and tracked as CVE-2026-25262, has rattled the security community. First confirmed by Qualcomm in April 2025, full technical details are now available, exposing a backdoor capable of total device takeover and data destruction.

snapdragon exploit takes over device

The Sahara Protocol and BootROM Flaw

The issue lies deep in the BootROM, the silicon-hardcoded firmware that runs first when a device powers up. Because this code is etched into the hardware itself, standard OTA software updates can’t touch it, making patches nearly impossible.

Researchers uncovered a major weakness in Qualcomm‘s Sahara protocol handling. For those who work with device flashing, Sahara manages low-level communication in Emergency Download (EDL) mode to load critical software before the main OS starts.

With just a few minutes of physical access, attackers can exploit this to sidestep the entire secure boot chain. Once inside the application processor, they gain the ability to:

  • Install persistent backdoors that survive reboots.
  • Pull sensitive data like passwords, files, contacts, and real-time location.
  • Take over device sensors for covert camera and microphone access.

The malware even fakes a system reboot to throw off users. Clearing the infection often requires draining the battery completely to wipe volatile memory, and detection remains extremely challenging.

Affected Chipsets and Devices

While newer flagships like Snapdragon 8 Elite have stronger defenses, this flaw hits many older and mid-range chips still in widespread use.

You May Also Like
Recommended
1

Android 17 QPR3 Beta 1 arrives for Pixel with over 20 bug fixes

android 17 beta update
2

Android 17 QPR2 Beta 6.1 fixes a Pixel 11 Pro Fold Face Unlock issue

Android 17 QPR2 Beta
3

Honor MagicOS 11 debuts September 15 with Glazed Architecture, faster YOYO

Honor MagicOS 11 debuts September 15 with Glazed Architecture, faster YOYO

Vulnerable Qualcomm Chipsets:

  • MSM8916 (Snapdragon 410) (Xiaomi REDMI 2)
  • SDX50 (Xiaomi Mi MIX 3 5G and Mi 9 Pro 5G)
  • MDM9x07
  • MDM9x45 (Xiaomi Mi 5, Mi 5s, Mi 5s Plus, Mi Note 2, Mi MIX)
  • MDM9x65
  • MSM8909
  • MSM8952

Real-World Impact

Physical access requirements limit mass remote attacks, but the risk to supply chains, repair shops, and targeted users remains severe. Compromised devices turn into perfect surveillance tools. With hardware deployed across consumer REDMI phones to industrial IoT systems, the potential fallout spans far beyond typical mobile threats.

Source: Kaspersky

Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source
Tags:#android#boot#exploit#kaspersky#malware#qualcomm#redmi#rom#snapdragonxiaomi
Recommended Deals
1 / 5
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

5.0
529.99
Buy on Amazon
* As an Amazon Associate, Droid Tools earns from qualifying purchases. Read our editorial policy
Cristian Penisoara
Cristian PenisoaraGuides Writer · Android Power User

Cristian Penisoara is a Guides Writer and Android specialist at Droid Tools. An Android user since version 2 and a professional event photographer, he combines technical curiosity with a detail-oriented approach - every guide he publishes is tested step-by-step on a real device before it goes live.

Next Story in OS

Android 17 QPR3 Beta 1 arrives for Pixel with over 20 bug fixes

Google has released Android 17 QPR3 Beta 1 to every still-supported Pixel device, from the Pixel 6a through the new Pixel 11 series, and the rollout arrived earlier than expected this afternoon. The update looks sizable, carrying fixes for at least 20 bugs that had carried over from QPR2. The beta ships as build DP11.260918.005 […]

→

Latest Stories

Samsung’s AI glasses confirmed for a November launch01

Samsung’s AI glasses confirmed for a November launch

02

What contractors should look for before hiring someone to build a business website

03

Google’s Pixel Referral Program is back with 10% off and Store credit

04

Android 17 QPR3 Beta 1 arrives for Pixel with over 20 bug fixes

Amazon Deals
5.0
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

Best Price
529.99
Buy

Top Deals

Google’s Pixel Referral Program is back with 10% off and Store credit

Deal
Google’s Pixel Referral Program is back with 10% off and Store credit

Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Deal
Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Apple Watch Series 12 vs Pixel Watch 5: how they compare

Deal
Apple Watch Series 12 vs Pixel Watch 5: how they compare
Recommended stories

Continue reading

More from this category →
android 17 beta update
OSOct 4, 2026

Android 17 QPR3 Beta 1 arrives for Pixel with over 20 bug fixes

Google has released Android 17 QPR3 Beta 1 to every still-supported Pixel device, from the Pixel 6a through the new Pixel 11 series, and the rollout arrived earlier than expected this afternoon. The update looks sizable, carrying fixes for at least 20 bugs that had carried over from QPR2. The beta ships as build DP11.260918.005 […]

By Robert Haba
Android 17 QPR2 Beta
OSSep 30, 2026

Android 17 QPR2 Beta 6.1 fixes a Pixel 11 Pro Fold Face Unlock issue

The previous Android 17 QPR2 Beta 6 update mostly focused on fixing bugs that had been plaguing devices for a while, including a substantial issue that caused phones to reboot simply from scrolling through content, along with fixes for letterboxed content leaking through the status bar during app transitions and a Pixel 9 Pro Fold […]

By Robert Haba
Honor MagicOS 11 debuts September 15 with Glazed Architecture, faster YOYO
OSSep 22, 2026

Honor MagicOS 11 debuts September 15 with Glazed Architecture, faster YOYO

Honor MagicOS 11 debuts on September 15 with a set of new features for eligible devices, ranging from a smoother, more fluid UI to a more capable AI assistant. Honor unveiled MagicOS 11 at its 2026 Global Developer Conference, and the company said the official version will open for unlimited testing right after the event, […]

By Robert Haba
honor magicos 11
OSSep 16, 2026

Honor MagicOS 11 to debut with hidden Power Saving

Honor MagicOS 11 is set to debut tomorrow at the company's developer conference, and ahead of the official launch, one of Honor's own officials has already revealed a new Power Saving feature coming with the software. XiaoFangge, Honor's Product Maintenance and Upgrade Manager, said MagicOS 11 will include what he described as a cute Easter […]

By Robert Haba
Next in queue

Read the next article

The next story loads as you reach the end. You can also load it using the button.

Comments & Discussions

Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.