When agencies broke the news of a new hole in Qualcomm chips, many minds undoubtedly went back to the events of autumn 2024, when the company had to face vulnerabilities found in the Snapdragon 8 Gen 1, a top-of-the-line 2022 chip installed on particularly expensive smartphones such as the Samsung Galaxy S22, Xiaomi 12, and OPPO Find X5. Now Kaspersky ICS CERT reports having identified a hardware-level security flaw, named CVE-2026-25262, but in the author’s opinion, it is not of equal importance compared to the one just mentioned since it affects mostly rather old chipsets. But let’s proceed in order.
AFFECTED SERIES
Documents reveal that the vulnerability was found in Qualcomm MDM9x07 (Snapdragon X5 LTE), MDM9x45 (Snapdragon X12 LTE), MSM8909 (Snapdragon 210), SDX50 (Snapdragon X50), and MSM8952. Therefore, it could be useful news to push undecided users to finally change their smartphones if the model is a few years old. Unable to list them all, we can limit ourselves to saying that the chips in question are housed, for example, in Oppo Reno 5G, OnePlus 7 Pro 5G, Xiaomi Mi Mix 3 5G, and on the Samsung Galaxy S10 5G and Galaxy C5.
THE VULNERABILITY
The critical issue was identified in a low-level communication tool that activates when the chip enters emergency recovery mode, called the Sahara protocol: at that moment, all protections can be bypassed; however, the risk is limited since physical access to the device is required, and there appear to be no possibilities for remote access.
The hacker who manages to get in would have the ability to steal passwords, intercept GPS location, and activate the microphone or camera without the user’s knowledge, obviously installing backdoors on the device. Particularly interesting is the fact that the compromise can even simulate the operating system reboot to keep spying functions active while the user thinks they are resetting the device.




