Home Wiki

Qualcomm

View on consumerrights.wiki ↗

Work in progress
This article has been flagged for additional work. Treat its claims as provisional.
Verification concerns
Editors have raised concerns about the verifiability of one or more claims.
Contents7
  1. Consumer-impact summary
  2. Incidents
  3. Restrictions on software modifications
  4. TOS change after acquistion of Arduino
  5. Products
  6. See also
  7. References

Article Status Notice: Inappropriate Tone/Word Usage

This article needs additional work to meet the wiki's Content Guidelines and be in line with our Mission Statement for comprehensive coverage of consumer protection issues. Specifically it uses wording throughout that is non-compliant with the Editorial guidelines of this wiki.

Learn more ▼

How You Can Help: If this is a non-Theme article (See: Article types):

  • Persuasive language should not be used in the Wiki's voice. Avoid loaded words, or the causing of unnecessary offense, wherever possible.
  • No direct attacks on named individuals or companies. Malice may be attributed to bad and proven offenders, but only through the use of quotation and citation - never in the Wiki's voice.

If this is a Theme article:

  • Where argumentation is used make sure it is clear and direct but not inflammatory. Avoid strong language, or causing unnecessary offense.
  • No direct attacks on named individuals or companies. Malice may be attributed to bad and proven offenders, in a formal and calm manner.

This notice will be removed once sufficient documentation has been added to establish the systemic nature of these issues. Once you believe the article is ready to have its notice removed, visit either the Moderator's noticeboard, or the Discord (join here) and post to the #appeals channel.

Qualcomm
Basic information
Founded 1985-07
Legal Structure Public
Industry Semiconductors, Computer hardware, Telecommunications
Also known as
Official website https://www.qualcomm.com/

Qualcomm Incorporated is a major fabless semiconductor manufacturer, famous for its Snapdragon line of system on a chip (SoC) targeted towards mobile phones, tablets, laptops among other types of devices. It also manufactures other components of mobile devices and telecommunication hardware including cellular modems, WiFi/Bluetooth chips and power management ICs.

Consumer-impact summary

  • User Freedom: Known for implementing measures against software modifications in mobile devices utilizing their processors. Also Qualcomm’s purchase of Arduino modified the terms of the purchase after the purchase was made with the changed TOS.
  • Market Control: Dominates in high-end mobile chips with indirect competition from Apple and Samsung. Higher competition with MediaTek in the medium to low-end mobile market, and with Intel, Broadcom and MediaTek in WiFi/Bluetooth chips. Competes with Apple, Intel and AMD in energy-efficient laptop processors.

Incidents

This is a list of all consumer-protection incidents this company is involved in. Any incidents not mentioned here can be found in the Qualcomm category.

Restrictions on software modifications

Qualcomm employs mechanisms in their Snapdragon SoCs that prevent users from running their own code or modifying firmware or operating system code on their devices. Such mechanisms include Secure Boot where each boot stage authorizes the next stage establishing a "chain of trust". On power-on, the SoC executes the Primary Boot Loader (PBL), stored in immutable read-only memory (ROM) etched on the silicon die making it physically impossible to modify. PBL loads and authorizes the eXtended Boot Loader (XBL), which in turn loads and authorizes the next stage which can be another bootloader or the operating system, all of which are stored in rewritable flash memory. The SoC contains a set of one-time programmable (OTP) electronic fuses within the SoC, which store cryptographic signing keys along with other parameters such as enabling Secure Boot and debugging flags. The signing keys are generated by Qualcomm and the device OEM and are used by the various boot stages to verify images loaded from flash memory. The keys are not provided to the end user, preventing any modifications to the software images.

A technical paper by Qualcomm[1] details the Secure Boot mechanism and clarifies the entities allowed to authorize software running on the end device:

The OTP eFuse configuration dictates the device custodian, who is commonly referred as the Original Equipment Manufacturer (OEM). The device OEM takes control of the device mutable software by loading a configuration file with their custom fuse values. The configuration file sets the fuses that enable secure boot and stores a cryptographic hash of the manufacturer public key certificate in the fuses reserved for it. Moreover, the immutable hardware has the ability to include the OEM fuse configuration in platform key derivations along with hardware secrets provisioned into the chip by Qualcomm Technologies and the device OEM. Secure boot restricts all keys with these bindings to software signed by that OEM and to them alone. One of the guiding principles of Qualcomm Secure boot is that no software runs without an authorization from the OEM.

The device OEM is set as the "device custodian" which controls the software that may run on the device. Further text describes other entities that may have a hand in authorizing software:

Besides the OEM there are other parties that have some type of stake in the final product. For instance, independent software vendors, content providers, and certification bodies want to ensure that their requirements are met with the product. Those parties may find it easier to get their assurance from a commonly used platform like the Qualcomm TEE, rather than inspect an individual OEM’s product. Hence, images that control assets linked to multiple stakeholders, or control shared resources on the SoC, are signed by both Qualcomm Technologies and the device manufacturer in a process known as double-signing. This is designed to ensure that any security-critical image can only be executed if it has been approved by Qualcomm Technologies and the device manufacturer.

Several entities are listed as being stakeholders in the final product, while no mention of the end user is made.

TOS change after acquistion of Arduino

On October 2025, Qualcomm acquired Arduino for an undisclosed amount, Shortly after this acquisition, the Terms of Use and Privacy Policy for Arduino was modified in a way that harmed consumers.

The following is an incomplete list of these changes:

  • Introduction of an irrevocable, perpetual license granted to Qualcomm over all user-uploaded content
  • Surveillance-style monitoring implemented for AI features
  • Patent infringement identification clause preventing users from identifying potential patent violations
  • Extended data retention of usernames for years after account deletion
  • Global data integration of all user data (including minors' data) into Qualcomm's ecosystem

Products

This is a list of the company's product lines with articles on this wiki.


Add your text below this box. Once this section is complete, delete this box by clicking on it and pressing backspace.


See also

References

  1. Secure Boot and Image Authentication Technical Overview, Qualcomm Technologies Inc., Retrieved 2025-10-08 (Archived)
Filed under