Junglewise Threat Intelligence

CVE-2026-24076: Qualcomm memory corruption in registry value processing

CVE-2026-24076 · Severity: medium · CVSS 6.7 · Published 2026-08-04

Technologies: Qualcomm Wcd9375, Qualcomm Cologne, Qualcomm Fastconnect 6200, Qualcomm Snapdragon 8cx Gen 3 Compute Platform Firmware, Qualcomm Fastconnect 6700, Qualcomm Snapdragon 7c\+ Gen 3 Compute, Qualcomm Wsa8845, Qualcomm Wcd9380, Qualcomm Snapdragon 7c Gen 2 Compute Platform, Qualcomm Qcm5430 Firmware, Qualcomm Qca0000, Qualcomm Wcd9370, Qualcomm Fastconnect 6200 Firmware, Qualcomm Wcd9378c Firmware, Qualcomm Wsa8845 Firmware, Qualcomm Wsa8835 Firmware, Qualcomm Video Collaboration Vc3 Platform, Qualcomm Fastconnect 7800 Firmware, Qualcomm Fastconnect 6900, Qualcomm Wcd9375 Firmware, Qualcomm Wsa8835, Qualcomm Sm6250, Qualcomm Wsa8845h Firmware, Qualcomm Cologne Firmware, Qualcomm SC8380XP Firmware, Qualcomm Wsa8830, Qualcomm Wcd9378c, Qualcomm Qcm6490, Qualcomm Wsa8840, Qualcomm Snapdragon 7c Compute Platform Firmware, Qualcomm Qca6391 Firmware, Qualcomm FastConnect 6800 Firmware, Qualcomm AQT1000 Firmware, Qualcomm Wcd9385, Qualcomm Wsa8845h, Qualcomm Qcm6490 Firmware, Qualcomm Wsa8830 Firmware, Qualcomm Fastconnect 6700 Firmware, Qualcomm SM6250 Firmware, Qualcomm Qcm5430, Qualcomm Fastconnect 7800, Qualcomm Sc8380xp, Qualcomm Snapdragon 7c Compute Platform, Qualcomm Snapdragon 7c Gen 2 Compute Platform Firmware, Qualcomm Wsa8840 Firmware, Qualcomm Wcd9380 Firmware, Qualcomm Snapdragon 7c\+ Gen 3 Compute Firmware, Qualcomm Video Collaboration Vc3 Platform Firmware, Qualcomm Snapdragon 8cx Gen 3 Compute Platform, Qualcomm Qca0000 Firmware, Qualcomm Wcd9385 Firmware, Qualcomm Wcd9370 Firmware, Qualcomm Fastconnect 6900 Firmware. Vendors: Qualcomm.

Executive brief

A Qualcomm system component fails to validate the data type of registry values before processing them, leading to memory corruption. An attacker who can write to the system registry could trigger this vulnerability to crash the affected component or potentially execute arbitrary code, impacting system stability and security.

Technical details

This vulnerability involves memory corruption triggered by incorrect type handling when processing registry values through a direct query method. The affected component does not properly validate that registry entries match their expected data type before use, allowing an attacker to supply a registry value of an incorrect type. Exploitation requires local write access to the system registry. Successful exploitation could lead to crashes or potentially arbitrary code execution depending on the memory layout and attacker control over the malformed data.

Affected products

  • Qualcomm <UNKNOWN>

Timeline

  • 2026-08-04: disclosed

References

Related threats