Qualcomm Products Use-After-Free Vulnerability in HLOS Allowing Memory Corruption

Vulnerability

A use-after-free vulnerability has been identified in various chipsets by Qualcomm, leading to memory corruption during the deinitialization of a High-bandwidth Digital Content Protection (HDCP) session. This vulnerability affects several different chipsets, including those used in mobile platforms, automotive applications, and wireless communication.

Impact

Exploitation of this vulnerability can lead to memory corruption, which may be leveraged to execute arbitrary code or cause a denial-of-service condition by crashing the application or device.

Remediation

Qualcomm has developed patches for this vulnerability, which are being shared with device manufacturers. Instructions for applying the patch can be found in the January 2026 Qualcomm Security Bulletin.

Added: Jan 7, 2026, 1:34 PM
Updated: Jan 7, 2026, 1:34 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
1.3
exploitability
3.5
remediation
7.7
relevance
1.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.