Executive brief
A security vulnerability exists in the software powering various Qualcomm Snapdragon processors used in mobile devices and computing platforms. An attacker with local access to a device could exploit this flaw to cause system instability or gain unauthorized access to sensitive information. This could lead to a complete compromise of the device's security and data privacy.
Technical details
This vulnerability is a Use-After-Free (UAF) leading to memory corruption within Qualcomm's performance counter management logic. The flaw occurs when the system attempts to copy data from a memory source that has already been freed during a 'deselect' operation. A local attacker with low privileges could trigger this condition to corrupt kernel memory, potentially leading to local privilege escalation (LPE) or a denial-of-service (DoS) state. The issue is addressed in the Qualcomm May 2026 security bulletin.
Affected products
- Qualcomm Snapdragon Connectivity and Computing Platforms
Timeline
- 2026-05-04: advisory: Initial disclosure by Qualcomm and NVD