Qualcomm Products Weak Authentication Vulnerability Allowing User Throttling Bypass

Vulnerability

A cryptographic vulnerability has been identified in various chipsets used in Qualcomm products. This issue arises during PIN or password verification with Gatekeeper, where writes to the Replay Protected Memory Block (RPMB) can be dropped if the verification fails. This flaw could potentially allow a bypass of user throttling mechanisms.

Impact

Exploitation of this vulnerability could lead to unauthorized bypassing of user throttling, allowing for potentially abusive behavior such as repeated attempts in a short period.

Remediation

Qualcomm has notified customers about this vulnerability and is actively sharing patches with device manufacturers. Instructions for applying the patch can be found in the Qualcomm April 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.7
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.