Security researchers Alexander Kozlov and Sergey Anufrienko took on the challenge of breaking into Qualcomm MSM/MDM-family SoCs, which are the de facto standard modem platform for dozens of smartphone and IoT device brands (cars and heavy trucks, modern infrastructure, smart everything, etc.).
The authors demonstrate their approach to analyzing the Qualcomm MDM9207 chipset: starting from the earliest reachable component, finding ways to connect, bypassing protections, and finally fully taking over the chip.
The vulnerability was approved by Qualcomm back in May, but the final presentation was released only two days ago. Enjoy and share it with your product security colleagues.
More details:
Qualcomm BootROM: A Journey Through Sahara
Presentation [Youtube]: https://lnkd.in/d7cakDUQ
Slides [PDF]: https://i.blackhat.com/Asia-26/Presentations/BHAS26-Kozlov-Anufrienko-Qualcom-REV01.pdf


