ZeroHour

CVE-2026-24081

mass

Transient Bluetooth Denial-of-Service in Qualcomm Chipsets (Channel Map Over-Read)

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

A buffer over-read (CWE-126) in the Bluetooth channel-map handling of Qualcomm chipsets causes a transient denial of service when a channel map containing an insufficient number of used channels is processed while adaptive frequency hopping (AFH) is fully enabled. An attacker in adjacent wireless range, requiring no privileges or user interaction, can trigger the flaw by sending a crafted channel map to the vulnerable Bluetooth component. The impact is availability-only (CVSS availability: high; confidentiality/integrity: none), meaning the affected device's Bluetooth functionality transiently fails, with no code execution or data compromise. Any device running the affected Qualcomm Bluetooth firmware is potentially exposed, although the provided data does not enumerate specific chipset models or versions. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and exploitation has not been observed.

What to do: Monitor Qualcomm's security bulletin for CVE-2026-24081 and apply device firmware/OS updates from your OEM for affected Qualcomm Bluetooth components as they are released. Until patched, disable Bluetooth when not needed in environments with nearby untrusted devices, since the attack vector is adjacent (Bluetooth range). Inventory hardware for Qualcomm-based Bluetooth chipsets now so affected devices can be prioritized once the affected product list is published.

Affected
Qualcomm Bluetooth-enabled Qualcomm chipset firmware (flaw is in Bluetooth channel-map/adaptive frequency hopping processing; spe
Estimated exposure
masspotentially millions of devices (Qualcomm Bluetooth silicon ships in billions of smartphones, wearables and IoT devices; affected subset undisclosed) — Qualcomm is one of the largest suppliers of Bluetooth/SoC silicon for smartphones, wearables and IoT products, so even a partial affected-chip list plausibly spans millions of deployed devices, but the exact count is unknown because no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.

Weakness
CWE-126
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.