PatchSiren cyber security CVE debrief
CVE-2026-24082 Qualcomm, Inc. CVE debrief
CVE-2026-24082 is a high-severity memory corruption vulnerability in Qualcomm products. The vulnerability occurs when copying data from a freed source while executing a performance counter deselect operation. This vulnerability has a CVSS score of 7.8 and a CVSS severity of HIGH. Qualcomm has released a patch for this vulnerability, which is available in the May 2026 security bulletin.
- Vendor
- Qualcomm, Inc.
- Product
- Snapdragon
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-04
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-05-04
- Advisory updated
- 2026-06-29
Who should care
This vulnerability affects various Qualcomm products, including Snapdragon mobile platforms, QXM, and Robotics RB2/RB5. Users of affected products should apply the patch provided by Qualcomm to mitigate the vulnerability. The vulnerability requires local access and low privileges to exploit, making it a significant concern for users with physical access to the device.
Technical summary
The vulnerability occurs in the performance counter deselect operation, where data is copied from a freed source, leading to memory corruption. This can be exploited by an attacker with local access and low privileges to gain elevated privileges and execute arbitrary code. The vulnerability is caused by a use-after-free error in the performance counter deselect operation.
Defensive priority
High
Recommended defensive actions
- Apply the patch provided by Qualcomm in the May 2026 security bulletin.
- Ensure that all affected Qualcomm products are updated with the latest firmware.
- Implement additional security measures, such as memory protection and address space layout randomization (ASLR), to mitigate the vulnerability.
Evidence notes
The CVE record and NVD detail provide information on the vulnerability, its impact, and mitigation steps. The source item URL provides additional information on the vulnerability and its affected products.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-24082 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-24082
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-24082 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24082
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2026-bulletin.html
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.