CVE-2026-24082
7.8Qualcomm · Snapdragon (Multiple Products)
A use-after-free vulnerability in Qualcomm Snapdragon products allows local attackers to achieve high-impact memory corruption.
Executive summary
A critical use-after-free memory corruption vulnerability affects multiple Qualcomm Snapdragon chipsets and connectivity modules, posing significant local system compromise risks.
Vulnerability
This is a use-after-free vulnerability categorized as CWE-416, triggered when copying data from a freed source during a performance counter deselect operation. The CVSS vector indicates that a low-privileged local attacker can execute the attack without user interaction, leading to high impacts on confidentiality, integrity, and availability.
Business impact
A successful exploit of this vulnerability could allow an attacker with local access to compromise the underlying system, leading to complete data compromise, unauthorized access, or denial of service. The assigned CVSS score of 7.8 reflects the severity of the potential impact, though the local attack vector slightly mitigates the overall urgency compared to remote vulnerabilities.
Remediation
Immediate Action: Apply the vendor security updates provided in the Qualcomm May 2026 bulletin as soon as they become available for your specific device model.
Proactive Monitoring: Monitor system logs for unusual kernel crashes, unexpected reboots, or unauthorized attempts to execute performance counter operations.
Compensating Controls: Restrict local user access and enforce strict the principle of least privilege to minimize the risk of unauthorized local execution.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Security teams must prioritize identifying affected Qualcomm hardware within their device inventory and coordinate with device vendors to deploy firmware patches. Applying the official vendor update is essential to mitigate the risk of local memory corruption and system compromise.