Junglewise Threat Intelligence

CVE-2026-24082: Qualcomm Snapdragon memory corruption in performance counter deselect

CVE-2026-24082 · Severity: high · CVSS 7.8 · Published 2026-05-04

Vendors: Qualcomm.

Executive brief

A security vulnerability exists in the software powering various Qualcomm Snapdragon processors used in mobile devices and computing platforms. An attacker with local access to a device could exploit this flaw to cause system instability or gain unauthorized access to sensitive information. This could lead to a complete compromise of the device's security and data privacy.

Technical details

This vulnerability is a Use-After-Free (UAF) leading to memory corruption within Qualcomm's performance counter management logic. The flaw occurs when the system attempts to copy data from a memory source that has already been freed during a 'deselect' operation. A local attacker with low privileges could trigger this condition to corrupt kernel memory, potentially leading to local privilege escalation (LPE) or a denial-of-service (DoS) state. The issue is addressed in the Qualcomm May 2026 security bulletin.

Affected products

  • Qualcomm Snapdragon Connectivity and Computing Platforms

Timeline

  • 2026-05-04: advisory: Initial disclosure by Qualcomm and NVD

References

Related threats