PatchSiren cyber security CVE debrief
CVE-2026-24082 Qualcomm, Inc. CVE debrief
CVE-2026-24082 is a high-severity memory corruption vulnerability in Qualcomm products. The vulnerability occurs when copying data from a freed source while executing a performance counter deselect operation. This vulnerability has a CVSS score of 7.8 and a CVSS severity of HIGH. Qualcomm has released a patch for this vulnerability, which is available in the May 2026 security bulletin.
- Vendor
- Qualcomm, Inc.
- Product
- Snapdragon
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-04
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-05-04
- Advisory updated
- 2026-06-29
Who should care
This vulnerability affects various Qualcomm products, including Snapdragon mobile platforms, QXM, and Robotics RB2/RB5. Users of affected products should apply the patch provided by Qualcomm to mitigate the vulnerability. The vulnerability requires local access and low privileges to exploit, making it a significant concern for users with physical access to the device.
Technical summary
The vulnerability occurs in the performance counter deselect operation, where data is copied from a freed source, leading to memory corruption. This can be exploited by an attacker with local access and low privileges to gain elevated privileges and execute arbitrary code. The vulnerability is caused by a use-after-free error in the performance counter deselect operation.
Defensive priority
High
Recommended defensive actions
- Apply the patch provided by Qualcomm in the May 2026 security bulletin.
- Ensure that all affected Qualcomm products are updated with the latest firmware.
- Implement additional security measures, such as memory protection and address space layout randomization (ASLR), to mitigate the vulnerability.
Evidence notes
The CVE record and NVD detail provide information on the vulnerability, its impact, and mitigation steps. The source item URL provides additional information on the vulnerability and its affected products.
Official resources
-
CVE-2026-24082 CVE record
CVE.org
-
CVE-2026-24082 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
This article was generated with AI assistance based on the supplied source corpus.