Junglewise Threat Intelligence

CVE-2026-24073: Qualcomm decode statistics memory corruption

CVE-2026-24073 · Severity: high · CVSS 7.8 · Published 2026-09-17

Executive brief

A memory corruption vulnerability exists in Qualcomm software's decode statistics processing due to insufficient validation of offsets against structure boundaries. An attacker can exploit this to corrupt memory, potentially leading to crashes, information disclosure, or code execution depending on the attack context and system configuration.

Technical details

The vulnerability is a memory corruption flaw in decode statistics processing that results from inadequate validation of offset values against structure size limits. The root cause is a bounds-checking failure that allows an offset parameter to exceed valid memory boundaries within a target structure. Attack preconditions depend on how the vulnerable function is invoked, but exploitation typically requires the ability to control or influence the offset value passed to the decode statistics processor. An attacker with capability to trigger decode operations with malicious offset values can corrupt adjacent memory regions, leading to denial of service or potential code execution. Qualcomm has released security bulletins addressing this issue.

Affected products

  • Qualcomm <UNKNOWN>

Timeline

  • 2026-09-17: disclosed

References

Related threats