CVE-2026-24074
massMemory Corruption (Out-of-Bounds Write) in Qualcomm Chipsets via Oversized Offset/Length Copy
CVE-2026-24074 is a memory corruption flaw (CWE-787, out-of-bounds write) in Qualcomm chipset software, disclosed through Qualcomm's product security team. When processing data whose offset and length values are unusually large, a data copy operation exceeds buffer limits and writes past the end of the intended buffer. A local attacker who already has low privileges on a device (for example, via a malicious app) can trigger the condition to corrupt memory, potentially escalating privileges or gaining code execution in the affected component's context, with high impact on confidentiality, integrity and availability per the CVSS 7.8 score. The vulnerability affects devices running Qualcomm chipset firmware — a population that spans a large share of the world's Android smartphones and connected devices — though the specific affected components and version ranges are not listed in the available data. Exploitation status: the flaw is not on CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known.
What to do: Watch for the Qualcomm security bulletin entry covering CVE-2026-24074 and install OEM firmware/Android monthly security updates as soon as they deliver the fix; do not downgrade or defer device patch levels. Because the attack vector is local with low privileges required, limit risk in the interim by discouraging sideloading of untrusted apps and reviewing high-privilege app installs on managed fleets. Enterprises should check device patch levels and OEM advisories for affected model lists, then prioritize fleet-wide updates.
| Qualcomm | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.