Junglewise Threat Intelligence

CVE-2026-24077: Qualcomm wireless driver information disclosure in channel switch processing

CVE-2026-24077 · Severity: medium · CVSS 6.5 · Published 2026-08-04

Vendors: Qualcomm.

Executive brief

A wireless network driver component improperly processes channel switch information frames with malformed length fields, leading to information disclosure. An attacker can craft specially formatted wireless frames to read sensitive data from device memory, potentially exposing configuration details, credentials, or other protected information without requiring authentication or user interaction.

Technical details

The vulnerability exists in Qualcomm wireless driver code that processes IEEE 802.11 channel switch announcement frames. When a frame contains improperly formatted length fields in the channel switch element, the driver fails to properly validate or sanitize the length value before using it in memory operations. This out-of-bounds read condition allows an attacker to disclose adjacent memory contents. The attack requires network proximity to transmit malicious wireless frames but does not require authentication, association, or user interaction. No patch status is specified in the available advisory content.

Affected products

  • Qualcomm Wireless Driver <UNKNOWN>

Timeline

  • 2026-08-04: disclosed

References