A vulnerability called the "Qualcomm GBL Exploit" has been discovered that allows bootloader unlocking on recent Android smartphones built on Qualcomm SoCs, something that had previously been very difficult[1]. Devices powered by the Snapdragon 8 Elite Gen 5 are the main targets, and the unlock has already been confirmed on phones such as the Xiaomi 17 series[1]. Qualcomm has stated that fixes are already available, drawing attention from both the modding-freedom and the security angles.

What Is the "GBL Exploit"?

The GBL Exploit was found on devices that use Qualcomm chips and run Android 16[1]. It originates in how Qualcomm's vendor-specific Android Bootloader (ABL) loads the Generic Bootloader Library (GBL) from a partition called "efisp" during startup[1].

Normally, the system should verify whether the program being loaded is legitimate. However, the ABL was reportedly only checking that an app of the expected format exists in that partition, without verifying that it is actually the genuine GBL[1]. That oversight opens the door for unsigned code to run without any check, which forms the core of the GBL Exploit[1].

Multiple Vulnerabilities Chained Together to Reach an Unlock

Unlocking the bootloader does not work through this single flaw alone. The device runs a security mechanism called SELinux that blocks writes to areas that are not permitted by default[1]. Modifying the efisp partition requires loosening that mechanism, but doing so itself requires elevated privileges, so it cannot be done in a straightforward manner[1].

This is where another oversight comes in. Some fastboot commands accepted by Qualcomm's bootloader reportedly take unexpected arguments without validation, and this can be used as a foothold to loosen the security mechanism's settings[1]. On the Xiaomi 17 series, the permissions of a system-level app included in Hyper OS are further combined into the chain, making it possible to write a custom program to the efisp partition[1].

After a reboot, the planted program is loaded by the ABL without any verification, and it rewrites the internal values that indicate the bootloader's lock state[1]. The result is the same state as running the normal "fastboot oem unlock" command, that is, an unlocked device[1]. It is a textbook exploit chain in which several weaknesses are linked together to reach the goal.

Affected Devices and the Vendors' Response

So far, the unlock has been confirmed on the Xiaomi 17 series, the Redmi K90 Pro Max, and the POCO F8 Ultra, all of which run the Snapdragon 8 Elite Gen 5[1]. Because GBL is a mechanism introduced with Android 16, running that generation appears to be a prerequisite for now[1].

The GBL Exploit itself could affect the devices of any vendor that uses Qualcomm's ABL, with the exception of SAMSUNG, which uses its own bootloader called S-Boot[1]. However, the combination of vulnerabilities needed to reach an unlock differs from device to device, so the same procedure does not work on every model[1].

For its China-market phones, Xiaomi had set strict bootloader-unlock conditions based on time, a questionnaire, and a limited number of devices, to the point that many users had given up on unlocking altogether[1]. This new method bypassed those restrictions, but Xiaomi is reportedly about to patch the app used in the chain, and it may already have done so with the new Hyper OS 3.0.304.0 build that began rolling out in China[1].

Qualcomm also issued an official statement. The company said that developing technologies to support robust security and privacy is a priority, commended the Xiaomi ShadowBlade Security Lab researchers for using coordinated disclosure practices, and noted that fixes for the GBL-related research were made available to its customers (the device makers) in early March 2026[1]. Qualcomm encourages end users to apply security updates as soon as they become available from device makers[1].

What Users Should Keep in Mind

One thing to note is that applying the security update closes the loophole that was used for the unlock[1]. According to the report, many of the instructions circulating online tell users to disconnect their phones from the internet and avoid updating their firmware, creating a split between users who want to keep the unlock and users who want to update for safety[1].

It is also worth remembering that unlocking the bootloader can affect a device's warranty and some features, and a state in which unsigned programs can run can also become an entry point for malware. The GBL Exploit is both a way to free devices that were thought to be impossible to unlock and a vulnerability that lets external code write to areas that should be protected. Given that Qualcomm has already distributed fixes, applying the update is the basic course of action for ordinary users.

Summary

The GBL Exploit found around the bootloader of Qualcomm SoCs makes it possible to unlock the bootloader of Snapdragon 8 Elite Gen 5 phones by chaining together multiple vulnerabilities. While the unlock has actually been confirmed on the Xiaomi 17 series and other devices, both Qualcomm and Xiaomi have already moved to fix it. There are voices welcoming the modding freedom and voices wary of the security risk, and in the end it comes down to each user's decision on whether to apply the update.

出典:https://www.androidauthority.com/qualcomm-snapdragon-8-elite-gbl-exploit-bootloader-unlock-3648651/