Qualcomm Snapdragon Chipsets Use-After-Free Vulnerability in Automotive Audio

Vulnerability

A use-after-free vulnerability has been identified in various chipsets of Qualcomm Snapdragon products, specifically within the automotive audio domain. This vulnerability leads to memory corruption by accessing a buffer after it has been freed, particularly while processing IOCTL calls. The issue arises from improper synchronization between the assignment and deallocation of buffer resources, allowing for concurrent access to shared buffers and potential exploitation.

Impact

Exploitation of this vulnerability causes memory corruption, which can lead to arbitrary code execution or a denial-of-service condition by causing the system to crash.

Remediation

Qualcomm has released patches for this vulnerability, which can be applied by device manufacturers. Instructions for applying the patch are available in the Qualcomm March 2026 Security Bulletin.

Added: Mar 2, 2026, 5:57 PM
Updated: Mar 2, 2026, 9:37 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
2.9
remediation
7.7
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.