Qualcomm SCE-Mink Improper Access Control Vulnerability Allowing Memory Corruption

Vulnerability

A memory corruption vulnerability has been identified in the SCE-Mink component of Qualcomm chipsets. This issue arises when the trusted execution environment is accessed without the necessary privilege checks, leading to unauthorized memory modifications. The vulnerability affects several chipsets across different technology areas, including automotive, graphics, and modem-related platforms.

Impact

Exploitation of this vulnerability causes memory corruption, which can lead to undefined behavior in the application, including potential arbitrary code execution or causing a denial-of-service condition.

Remediation

Qualcomm has developed patches for this vulnerability, which are being shared with device manufacturers. Instructions for applying the patch can be found in the Qualcomm March 2026 Security Bulletin.

Added: Mar 2, 2026, 5:39 PM
Updated: Mar 2, 2026, 9:25 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
3.3
remediation
7.7
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.