Junglewise Threat Intelligence

CVE-2026-24080: Qualcomm fingerprint TA memory corruption in request parameter handling

CVE-2026-24080 · Severity: high · CVSS 7.8 · Published 2026-08-04

Technologies: Qualcomm Cologne, Qualcomm Fastconnect 6700, Qualcomm Wsa8845, Qualcomm Qca6595au, Qualcomm Wcd9378c Firmware, Qualcomm Wsa8845 Firmware, Qualcomm Fastconnect 7800 Firmware, Qualcomm Fastconnect 6900, Qualcomm Qca6696 Firmware, Qualcomm Wsa8845h Firmware, Qualcomm Qca6696, Qualcomm Cologne Firmware, Qualcomm Qam8295p Firmware, Qualcomm Wcd9378c, Qualcomm Qam8295p, Qualcomm Wsa8840, Qualcomm Wsa8845h, Qualcomm Fastconnect 6700 Firmware, Qualcomm Sa8295p, Qualcomm Fastconnect 7800, Qualcomm Wsa8840 Firmware, Qualcomm Sa8255p, Qualcomm Sa8295p Firmware, Qualcomm Fastconnect 6900 Firmware. Vendors: Qualcomm.

Executive brief

Qualcomm's fingerprint trusted application (TA) contains a memory corruption vulnerability when processing malformed request parameters. An attacker able to send crafted requests to the fingerprint service could trigger memory corruption, potentially leading to service crashes or unauthorized access to sensitive biometric data.

Technical details

A memory corruption vulnerability exists in Qualcomm's fingerprint trusted application when handling malformed request parameters. The vulnerability stems from insufficient validation of input parameters before processing them in memory operations. The fingerprint TA is a sensitive component handling biometric authentication; exploitation could occur from a local or adjacent network context with access to the vulnerable service. An attacker can cause memory corruption leading to denial of service or potential privilege escalation within the trusted execution environment. Patches are expected to be available through Qualcomm's security bulletins.

Affected products

  • Qualcomm fingerprint TA <UNKNOWN>

Timeline

  • 2026-08-04: disclosed

References

Related threats