CVE-2021-30327 is a buffer overflow in Sahara protocol command processing affecting Qualcomm Snapdragon Mobile, Compute, Auto, IoT, Connectivity, and Voice & Music platforms. Processing malformed or otherwise crafted protocol commands can overflow a buffer and overwrite secure configuration data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone Python exploit/tool named 'Katana' that automates a Qualcomm EDL/BootROM exploitation and bootloader-unlock workflow for supported Snapdragon 845 Android devices. It is not a framework module. The codebase is small and organized into a main orchestrator (main.py), USB/Sahara transport handling (modules/sahara.py), payload upload logic (modules/upload.py), DevPrg XML storage operations (modules/devprg.py), GPT parsing (modules/gpt.py), a progress bar helper, and SoC-specific constants/payload paths in soc_data.py. Main capability: the tool connects over USB to a Qualcomm device in EDL mode, speaks the Sahara protocol, uploads a BootROM exploit payload, manipulates the target's state machine to trigger exploitation, then uploads a DevPrg programmer to gain raw storage access. It then identifies the ABL partition by parsing GPT data from eMMC/UFS, backs up the original ABL to a local file, flashes a replacement image ('oxygen.elf'), reboots the device back into EDL, executes an additional payload ('securepwn'), instructs the operator to use desired options and reboot to EDL again, then re-exploits and restores the original ABL backup. The exploit is clearly offensive/active rather than a detector: it performs direct device compromise and partition flashing. There are no network callbacks or remote C2 endpoints; the attack surface is USB/physical access to a device in Qualcomm EDL mode. The most fingerprintable observables are the Qualcomm EDL USB identifier 0x05C6:0x9008, the Sahara protocol usage, the DevPrg XML commands (<configure>, <read>, <program>, <power>, <getstorageinfo>), the GPT partition names 'abl_a'/'abl', and the expected local resource ELF files. The repository does not include the actual ELF payload binaries in the provided file list, so the Python code is an operational orchestrator around external payloads rather than a self-contained exploit implementation.
This repository is a standalone Python proof-of-concept/operational exploit for Qualcomm BootROM vulnerability CVE-2021-30327, branded 'Katana'. It is not part of a larger exploit framework. The repo is small and focused: README.md documents the vulnerability and usage, katana.py contains the exploit logic and USB/Sahara protocol handling, soc_data.py contains SoC-specific exploit constants and staged overwrite buffers, and requirements.txt lists Python dependencies (pyusb/libusb/coloredlogs). The exploit targets Qualcomm devices in Emergency Download (EDL) / Sahara mode over USB, specifically searching for VID:PID 05c6:9008. The core capability is BootROM code execution by abusing the Sahara reset-state-machine command (0x13). According to the README and code flow, repeated invocations of this command decrement the stack pointer without proper guarding, eventually exhausting stack space and corrupting adjacent memory. The exploit then leverages this corruption to overlap stack buffers with global function pointer tables so that cryptographic modular exponentiation dispatch is redirected into attacker-controlled shellcode loaded as part of the modulus/signature handling path. Operationally, katana.py connects to the USB device, negotiates Sahara, uploads an attacker-provided payload binary, sends null padding/chunks as required by the target SoC profile, repeatedly issues command 0x13 to trigger the memory corruption, and finally sends SoC-specific staged data blobs (finish_payload_rx_stage1/stage2) to complete execution redirection. The script logs that the BootROM is 'pwned' once shellcode execution is expected. If a specific payload type is detected, it can then release and reconnect to USB, re-negotiate Sahara, and upload a Firehose/DevPrg loader, enabling follow-on actions such as using test-signed firehoses. The included soc_data.py shows explicit support data for at least the Qualcomm SDM845 SoC, including reset counts, null-send counts, and large binary stage buffers. This indicates the exploit is highly target-specific and depends on precise memory layout/timing values per SoC. Overall, the repository is a real exploit implementation for physical/USB attack scenarios against vulnerable Qualcomm devices, providing BootROM-level arbitrary code execution rather than mere detection.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.