Qualcomm
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Qualcomm product.
RSS Feeds for Qualcomm security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Qualcomm products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Qualcomm Sorted by Most Security Vulnerabilities since 2018
Known Exploited Qualcomm Vulnerabilities
The following Qualcomm vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Qualcomm Multiple Chipsets Memory Corruption Vulnerability |
Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. CVE-2026-21385 Exploit Probability: 0.4% |
March 3, 2026 |
| Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability |
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. CVE-2025-21479 Exploit Probability: 0.1% |
June 3, 2025 |
| Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability |
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. CVE-2025-21480 Exploit Probability: 1.5% |
June 3, 2025 |
| Qualcomm Multiple Chipsets Use-After-Free Vulnerability |
Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome. CVE-2025-27038 Exploit Probability: 1.1% |
June 3, 2025 |
| Qualcomm Multiple Chipsets Use-After-Free Vulnerability |
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory. CVE-2024-43047 Exploit Probability: 1.7% |
October 8, 2024 |
| Qualcomm Multiple Chipsets Integer Overflow Vulnerability |
Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. CVE-2023-33107 Exploit Probability: 0.2% |
December 5, 2023 |
| Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability |
Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. CVE-2023-33106 Exploit Probability: 0.2% |
December 5, 2023 |
| Qualcomm Multiple Chipsets Use-After-Free Vulnerability |
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP. CVE-2023-33063 Exploit Probability: 0.4% |
December 5, 2023 |
| Qualcomm Multiple Chipsets Use-After-Free Vulnerability |
Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress. CVE-2022-22071 Exploit Probability: 0.6% |
December 5, 2023 |
| Qualcomm Multiple Chipsets Improper Input Validation Vulnerability |
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables CVE-2020-11261 Exploit Probability: 1.1% |
December 1, 2021 |
| Qualcomm Improper Error Handling Vulnerability |
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. CVE-2021-1906 Exploit Probability: 0.1% |
November 3, 2021 |
| Qualcomm Use-After-Free Vulnerability |
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously CVE-2021-1905 Exploit Probability: 1.0% |
November 3, 2021 |
By the Year
In 2026 there have been 46 vulnerabilities in Qualcomm with an average score of 7.3 out of ten. Last year, in 2025 Qualcomm had 122 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Qualcomm in 2026 could surpass last years number. Last year, the average CVE base score was greater by 0.32
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 46 | 7.31 |
| 2025 | 122 | 7.63 |
| 2024 | 6 | 7.82 |
| 2023 | 9 | 8.22 |
| 2022 | 52 | 7.58 |
| 2021 | 227 | 7.67 |
| 2020 | 170 | 7.10 |
| 2019 | 150 | 9.80 |
| 2018 | 227 | 0.00 |
It may take a day or so for new Qualcomm vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Qualcomm Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-21385 | Mar 02, 2026 |
Qualcomm Memory Corruption via Alignment AllocationMemory corruption while using alignments for memory allocation. |
|
| CVE-2025-59603 | Mar 02, 2026 |
Qualcomm Memory Corruption via Nonstandard Buffer AddressMemory Corruption when processing invalid user address with nonstandard buffer address. |
|
| CVE-2025-59600 | Mar 02, 2026 |
Memory Corruption via unchecked buffer overflow in Qualcomm componentMemory Corruption when adding user-supplied data without checking available buffer space. |
|
| CVE-2025-47386 | Mar 02, 2026 |
Memory Corruption via IOCTL in Qualcomm driver under concurrent accessMemory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs. |
|
| CVE-2025-47385 | Mar 02, 2026 |
Qualcomm TEE Memory Corruption via Privilege EscalationMemory Corruption when accessing trusted execution environment without proper privilege check. |
|
| CVE-2025-47384 | Mar 02, 2026 |
Transient DoS via MAC Config ID overflow (Qualcomm)Transient DOS when MAC configures config id greater than supported maximum value. |
|
| CVE-2025-47383 | Mar 02, 2026 |
Qualcomm VoWiFi Weak Config Causing Crypto Issue (CVE-2025-47383)Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. |
|
| CVE-2025-47381 | Mar 02, 2026 |
Qualcomm IOCTL Shared Buffer Concurrency Memory CorruptionMemory Corruption while processing IOCTL calls when concurrent access to shared buffer occurs. |
|
| CVE-2025-47379 | Mar 02, 2026 |
Qualcomm Snapdragon Shared Buffer Memory CorruptionMemory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources. |
|
| CVE-2025-47378 | Mar 02, 2026 |
Qualcomm HLOS Boot Loader Crypto Issue via Shared VM RefCryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain. |
|
| CVE-2025-47377 | Mar 02, 2026 |
Qualcomm Driver IOCTL Buffer Use-After-Free (CVE-2025-47377)Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls. |
|
| CVE-2025-47376 | Mar 02, 2026 |
Qualcomm Driver Concurrent IOCTL Shared Buffer Mem CorruptionMemory Corruption when concurrent access to shared buffer occurs during IOCTL calls. |
|
| CVE-2025-47375 | Mar 02, 2026 |
Qualcomm Kernel Driver: Concurrent IOCTLs Lead to Memory CorruptionMemory corruption while handling different IOCTL calls from the user-space simultaneously. |
|
| CVE-2025-47373 | Mar 02, 2026 |
Qualcomm TEE memory corruption via TA length bypassMemory Corruption when accessing buffers with invalid length during TA invocation. |
|
| CVE-2025-47371 | Mar 02, 2026 |
Transient DoS via invalid LTE RLC packet on Qualcomm UETransient DOS when an LTE RLC packet with invalid TB is received by UE. |
|
| CVE-2025-47402 | Feb 02, 2026 |
Transient DoS via Oversize Auth IE in 802.11 FrameTransient DOS when processing a received frame with an excessively large authentication information element. |
|
| CVE-2025-47399 | Feb 02, 2026 |
Memory Corruption in sensor driver IOCTL (invalid params)Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters. |
|
| CVE-2025-47398 | Feb 02, 2026 |
GPU Mem Buffer Dealloc Memory Corruption VulnerabilityMemory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers. |
|
| CVE-2025-47397 | Feb 02, 2026 |
GPU DMA Memory Corruption via Unchecked IOMMU Mapping ErrorsMemory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. |
|
| CVE-2025-47366 | Feb 02, 2026 |
Android TEE Crypto Flaw via HLOS InputCryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input. |
|
| CVE-2025-47364 | Feb 02, 2026 |
Memory Corruption in Partition Offset CalculationMemory corruption while calculating offset from partition start point. |
|
| CVE-2025-47363 | Feb 02, 2026 |
Memory Corruption in Partition Size Calc (Oversized)Memory corruption when calculating oversized partition sizes without proper checks. |
|
| CVE-2025-47359 | Feb 02, 2026 |
Memory Corruption via Concurrent Free API misuseMemory Corruption when multiple threads simultaneously access a memory free API. |
|
| CVE-2025-47358 | Feb 02, 2026 |
Linux Kernel Mem_Free Exploit via User-Space Address LeakMemory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inadvertently. |
|
| CVE-2025-47396 | Jan 06, 2026 |
Qualcomm Secure OS memory corruption on lowmemory launchMemory corruption occurs when a secure application is launched on a device with insufficient memory. |
|
| CVE-2025-47395 | Jan 06, 2026 |
Qualcomm WLAN FW DoS via Vendor-Specific IE parseTransient DOS while parsing a WLAN management frame with a Vendor Specific Information Element. |
|
| CVE-2025-47394 | Jan 06, 2026 |
Qualcomm Overlapping Buffer Copy Memory CorruptionMemory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations. |
|
| CVE-2025-47393 | Jan 06, 2026 |
Qualcomm kernel driver memory corruption CVE-2025-47393Memory corruption when accessing resources in kernel driver. |
|
| CVE-2025-47388 | Jan 06, 2026 |
Memory Corruption in Qualcomm DSP Driver via Unaligned Page PassingMemory corruption while passing pages to DSP with an unaligned starting address. |
|
| CVE-2025-47380 | Jan 06, 2026 |
Qualcomm Sensor Driver IOCTL Memory Corruption (CVE-2025-47380)Memory corruption while preprocessing IOCTLs in sensors. |
|
| CVE-2025-47369 | Jan 06, 2026 |
Qualcomm kernel driver info disclosure via weak hashed session ID IOCTLInformation disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID. |
|
| CVE-2025-47356 | Jan 06, 2026 |
Concurrent Thread Access Causing Mem Corruption in QualcommMemory Corruption when multiple threads concurrently access and modify shared resources. |
|
| CVE-2025-47346 | Jan 06, 2026 |
Memory corruption in QC QSEE secure logging cmdMemory corruption while processing a secure logging command in the trusted application. |
|
| CVE-2025-47348 | Jan 06, 2026 |
Memory corruption in Qualcomm QSEE Trusted ApplicationMemory corruption while processing identity credential operations in the trusted application. |
|
| CVE-2025-47345 | Jan 06, 2026 |
CVE-2025-47345: Crypto Flaw on Qualcomm License Encryption (Android)Cryptographic issue may occur while encrypting license data. |
|
| CVE-2025-47343 | Jan 06, 2026 |
Qualcomm Snapdragon Video Engine: Memory Corruption via Video Session InitMemory corruption while processing a video session to set video parameters. |
|
| CVE-2025-47344 | Jan 06, 2026 |
CVE-2025-47344: Memory Corruption in Qualcomm Sensor UtilityMemory corruption while handling sensor utility operations. |
|
| CVE-2025-47339 | Jan 06, 2026 |
Qualcomm Snapdragon HDCP Deinit mem corruptionMemory corruption while deinitializing a HDCP session. |
|
| CVE-2025-47337 | Jan 06, 2026 |
Qualcomm Memory Corruption in Sync Object during Concurrent OpsMemory corruption while accessing a synchronization object during concurrent operations. |
|
| CVE-2025-47336 | Jan 06, 2026 |
Qualcomm Sensor HAL memory corruption on register readMemory corruption while performing sensor register read operations. |
|
| CVE-2025-47335 | Jan 06, 2026 |
Qualcomm Clock Config Parser Memory CorruptionMemory corruption while parsing clock configuration data for a specific hardware type. |
|
| CVE-2025-47334 | Jan 06, 2026 |
Qualcomm Camera driver: sharedbuffer memory corruption CVE202547334Memory corruption while processing shared command buffer packet between camera userspace and kernel. |
|
| CVE-2025-47333 | Jan 06, 2026 |
Qualcomm Crypto Driver: Buffer Mapping Memory CorruptionMemory corruption while handling buffer mapping operations in the cryptographic driver. |
|
| CVE-2025-47332 | Jan 06, 2026 |
Qualcomm Config Call Memory CorruptionMemory corruption while processing a config call from userspace. |
|
| CVE-2025-47331 | Jan 06, 2026 |
Qualcomm firmware info disclosure via event processingInformation disclosure while processing a firmware event. |
|
| CVE-2025-47330 | Jan 06, 2026 |
Qualcomm Video Firmware Parser DoS during Packet HandlingTransient DOS while parsing video packets received from the video firmware. |
|
| CVE-2025-47387 | Dec 18, 2025 |
Memory Corruption in JPEG IOCTL Handler of Device DriverMemory Corruption when processing IOCTLs for JPEG data without verification. |
|
| CVE-2025-47382 | Dec 18, 2025 |
Bootloader memory corruption via invalid firmware load (CVE-2025-47382)Memory corruption while loading an invalid firmware in boot loader. |
|
| CVE-2025-47372 | Dec 18, 2025 |
Memory Corruption in ELF Parser: Oversized Size AbuseMemory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication. |
|
| CVE-2025-47350 | Dec 18, 2025 |
Linux Kernel Concurrent mmap/unmap Memory Corruption CVE-2025-47350Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application. |
|