CVE-2026-24088
HighPublished
Missing Authentication for Critical Function in Boot
- Published
- Jun 1, 2026
- Updated
- Jun 3, 2026
- Assigning CNA
- qualcomm
- Evidence observed
- Oct 2, 2026
Primary CVSS
8.2/ 10High
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H0.1%
Low · next 30 days
- Percentile
- 0.1%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
Sources
- POCO-M7-Plus-JailbreakExploit
Temporary Root Research on Poco M7 Plus (SM6375) via Qualcomm GBL Exploit (CVE-2026-24088) + GhostLock Kernel Analysis (CVE-2026-43499)
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.