
Kaspersky ICS CERT has publicly detailed a critical hardware vulnerability hitting a wide array of Qualcomm Snapdragon chipsets. The exploit, presented at Black Hat Asia 2026 on April 23 and tracked as CVE-2026-25262, has rattled the security community. First confirmed by Qualcomm in April 2025, full technical details are now available, exposing a backdoor capable of total device takeover and data destruction.

The Sahara Protocol and BootROM Flaw
The issue lies deep in the BootROM, the silicon-hardcoded firmware that runs first when a device powers up. Because this code is etched into the hardware itself, standard OTA software updates can’t touch it, making patches nearly impossible.
Researchers uncovered a major weakness in Qualcomm‘s Sahara protocol handling. For those who work with device flashing, Sahara manages low-level communication in Emergency Download (EDL) mode to load critical software before the main OS starts.
With just a few minutes of physical access, attackers can exploit this to sidestep the entire secure boot chain. Once inside the application processor, they gain the ability to:
- Install persistent backdoors that survive reboots.
- Pull sensitive data like passwords, files, contacts, and real-time location.
- Take over device sensors for covert camera and microphone access.
The malware even fakes a system reboot to throw off users. Clearing the infection often requires draining the battery completely to wipe volatile memory, and detection remains extremely challenging.
Affected Chipsets and Devices
While newer flagships like Snapdragon 8 Elite have stronger defenses, this flaw hits many older and mid-range chips still in widespread use.
Vulnerable Qualcomm Chipsets:
- MSM8916 (Snapdragon 410) (Xiaomi REDMI 2)
- SDX50 (Xiaomi Mi MIX 3 5G and Mi 9 Pro 5G)
- MDM9x07
- MDM9x45 (Xiaomi Mi 5, Mi 5s, Mi 5s Plus, Mi Note 2, Mi MIX)
- MDM9x65
- MSM8909
- MSM8952
Real-World Impact
Physical access requirements limit mass remote attacks, but the risk to supply chains, repair shops, and targeted users remains severe. Compromised devices turn into perfect surveillance tools. With hardware deployed across consumer REDMI phones to industrial IoT systems, the potential fallout spans far beyond typical mobile threats.
Source: Kaspersky

Google Pixel Watch 4
Keep Reading
New leaks are offering the clearest look yet at HyperOS 4, and they suggest Xiaomi is preparing the biggest visual overhaul in the software’s history, including a redesigned interface and refreshed wallpapers. Liquid Glass Interface Leak Details Screenshots reportedly pulled from internal Xiaomi 18-series prototypes running an early Android 17-based build of HyperOS 4 reveal […]

Xiaomi has started rolling out stable Android 17 to the Xiaomi 17, Xiaomi 17 Ultra, and Xiaomi 17T Pro, packaged under the HyperOS 3 label. A Confusing Label, But a Real Platform Jump The HyperOS 3 branding is the same one Xiaomi already used for its Android 16 rollout, which makes the naming a bit […]

Google is rolling out the stable Android 17 and Wear OS 7 updates for compatible Pixel phones and watches. Beyond the new features these releases bring, both updates come packed with bug fixes and general improvements aimed at smoothing out the overall experience. Many of the changes target long-standing annoyances, while several underlying improvements should […]

Android 17 has just arrived on Google Pixel phones, and it’s set to reach Xiaomi devices soon as well. For Xiaomi users, though, this upgrade carries considerably more weight than usual — the upcoming HyperOS 4 skin is reportedly bringing a substantial software and architectural overhaul rather than the typical incremental yearly refresh. Beyond the […]

Android 17 QPR1 Beta 6 has arrived for Google Pixel devices, bringing a mix of new features and bug fixes. This release also marks the Platform Stability milestone for the operating system, laying the groundwork for its transition toward a stable release. Alongside the specific bug fixes Google detailed for this build, the update introduces […]

Honor introduced a new term to the industry, “Agentic OS,” on the opening day of MWC26 in Shanghai, outlining several defining characteristics of this operating system concept along with features that will arrive for users through the upcoming MagicOS 11 update. The reveal took place during the MWC 26 first-day event on June 24, where […]






Comments & Discussions
Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.