ZeroHour

CVE-2026-24073

mass

Out-of-Bounds Write in Qualcomm Decode Statistics Processing

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-24073 is a memory corruption flaw (CWE-787, out-of-bounds write) in software assigned by Qualcomm's product-security CNA that processes decode statistics, caused by insufficient validation of an offset against the size of the structure it indexes into. A local attacker with low privileges can trigger the flaw by getting the affected component to process malformed decode statistics data, with no user interaction required. Successful exploitation corrupts adjacent memory and carries high impact to confidentiality, integrity, and availability (CVSS 3.1 score of 7.8, AV:L/AC:L/PR:L/UI:N), consistent with local code execution or privilege escalation in the context of the affected component. Any device running the affected Qualcomm component is exposed; the specific chipset, driver, or component name is not detailed in the available data. No exploitation is currently known: the flaw is not listed in CISA KEV and no public proof-of-concept exists.

What to do: Monitor Qualcomm's security bulletin (qualcomm.com/security) for CVE-2026-24073 to identify the exact affected chipsets/components and fixed versions, then apply the corresponding OEM firmware or Android security update when released. Until patched, limit local attack surface on affected devices by avoiding installation of untrusted apps, since exploitation requires local access with low privileges. Confirm your device's chipset and update status with the handset or device OEM's support pages.

Affected
Qualcomm
Estimated exposure
masspotentially hundreds of millions of devices (exact scope unknown pending Qualcomm's bulletin) — Qualcomm silicon and software components are deployed in the majority of Android handsets plus IoT and automotive devices, so bulletin-scoped chipset components typically affect device counts well above one million, though the specific…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.

Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.