Junglewise Threat Intelligence

CVE-2026-24085: Qualcomm Snapdragon memory corruption in display command line processing

CVE-2026-24085 · Severity: high · CVSS 7.2 · Published 2026-06-01

Technologies: Qualcomm Snapdragon Mobile. Vendors: Qualcomm.

Executive brief

A security vulnerability exists in Qualcomm chipsets when processing command line display information. An attacker with physical access to a device and high-level privileges could exploit this flaw to corrupt system memory. This could lead to a complete compromise of the device's integrity and confidentiality, potentially allowing for unauthorized access to sensitive data or permanent device impairment.

Technical details

A stack-based buffer overflow (CWE-121) exists in Qualcomm firmware during the processing of display command line information. The root cause is the improper initialization of a variable, which leads to memory corruption. Exploitation requires physical access to the device (AV:P) and high privileges (PR:H). If successfully exploited, an attacker can achieve a scope jump (S:C) and gain full control over the confidentiality, integrity, and availability of the system. The vulnerability was disclosed in the June 2026 Qualcomm Security Bulletin.

Affected products

  • Qualcomm Snapdragon Mobile

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory

References

Related threats