Qualcomm
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Qualcomm product.
RSS Feeds for Qualcomm security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Qualcomm products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Qualcomm Sorted by Most Security Vulnerabilities since 2018
Known Exploited Qualcomm Vulnerabilities
The following Qualcomm vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Qualcomm Multiple Chipsets Memory Corruption Vulnerability |
Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. CVE-2026-21385 Exploit Probability: 1.2% |
March 3, 2026 |
| Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability |
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. CVE-2025-21479 Exploit Probability: 0.8% |
June 3, 2025 |
| Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability |
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. CVE-2025-21480 Exploit Probability: 0.5% |
June 3, 2025 |
| Qualcomm Multiple Chipsets Use-After-Free Vulnerability |
Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome. CVE-2025-27038 Exploit Probability: 1.0% |
June 3, 2025 |
| Qualcomm Multiple Chipsets Use-After-Free Vulnerability |
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory. CVE-2024-43047 Exploit Probability: 0.7% |
October 8, 2024 |
| Qualcomm Multiple Chipsets Integer Overflow Vulnerability |
Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. CVE-2023-33107 Exploit Probability: 0.7% |
December 5, 2023 |
| Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability |
Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. CVE-2023-33106 Exploit Probability: 0.8% |
December 5, 2023 |
| Qualcomm Multiple Chipsets Use-After-Free Vulnerability |
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP. CVE-2023-33063 Exploit Probability: 0.7% |
December 5, 2023 |
| Qualcomm Multiple Chipsets Use-After-Free Vulnerability |
Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress. CVE-2022-22071 Exploit Probability: 0.4% |
December 5, 2023 |
| Qualcomm Multiple Chipsets Improper Input Validation Vulnerability |
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables CVE-2020-11261 Exploit Probability: 1.6% |
December 1, 2021 |
| Qualcomm Improper Error Handling Vulnerability |
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. CVE-2021-1906 Exploit Probability: 0.5% |
November 3, 2021 |
| Qualcomm Use-After-Free Vulnerability |
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously CVE-2021-1905 Exploit Probability: 1.5% |
November 3, 2021 |
By the Year
In 2026 there have been 152 vulnerabilities in Qualcomm with an average score of 7.4 out of ten. Last year, in 2025 Qualcomm had 122 security vulnerabilities published. That is, 30 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.24
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 152 | 7.39 |
| 2025 | 122 | 7.63 |
| 2024 | 6 | 7.82 |
| 2023 | 9 | 8.22 |
| 2022 | 52 | 7.58 |
| 2021 | 227 | 7.67 |
| 2020 | 170 | 7.10 |
| 2019 | 150 | 9.80 |
| 2018 | 227 | 0.00 |
It may take a day or so for new Qualcomm vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Qualcomm Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-57559 | Oct 06, 2026 |
Memory corruption in Qualcomm service request processingMemory corruption while processing service requests. |
|
| CVE-2026-57555 | Oct 06, 2026 |
Qualcomm Memory Corruption in System Service RoutinesMemory Corruption when executing system service routines due to improper handling of user input buffers. |
|
| CVE-2026-57554 | Oct 06, 2026 |
Qualcomm FastRPC: Memory Corruption on Concurrent Perf Counter AccessMemory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations. |
|
| CVE-2026-57546 | Oct 06, 2026 |
Qualcomm Modem Firmware DOS via Zero-Sized Config OverrideTransient DOS when processing a continuous receive command with a zero-sized global configuration override. |
|
| CVE-2026-57545 | Oct 06, 2026 |
Qualcomm GPU Driver: Memory Corruption via Draw Object InconsistencyMemory corruption when processing draw objects of incorrect type during graphics command list execution. |
|
| CVE-2026-57537 | Oct 06, 2026 |
Memory Corruption in Qualcomm Mapping SDK via Concurrent AccessMemory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization. |
|
| CVE-2026-25302 | Oct 06, 2026 |
Qualcomm: Auth Bypass for Unsigned Images on Non-ELF PartitionsCryptographic Issue when processing non-ELF partitions, authentication and signature checks are bypassed, allowing unsigned or corrupted images to be mounted and processed. |
|
| CVE-2026-25291 | Oct 06, 2026 |
Qualcomm Memory corruption in shared memory page lists (CVE-2026-25291)Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms. |
|
| CVE-2026-25274 | Oct 06, 2026 |
Qualcomm Snapdragon SoC Memory Corruption via Un-Sync DMA BufferMemory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization. |
|
| CVE-2026-25273 | Oct 06, 2026 |
Qualcomm Camera Driver OOB Write CVE-2026-25273Memory Corruption when processing camera operations due to out-of-bounds write during driver updates. |
|
| CVE-2026-25272 | Oct 06, 2026 |
Memory Corruption in Qualcomm Camera CRE Driver via Buffer Overflow during HW UpdateMemory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation. |
|
| CVE-2026-25270 | Oct 06, 2026 |
Android Camera Driver Memory Corruption via Invalid CmdBuffer LengthMemory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver. |
|
| CVE-2026-25269 | Oct 06, 2026 |
Qualcomm Camera Driver Memory Corruption via Excessive Batch/IO Buffer ConfigMemory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size. |
|
| CVE-2026-25267 | Oct 06, 2026 |
Qualcomm Secure Bootloader Mem Corruption via Page Table RewriteMemory corruption when non-secure loader rewrites page tables before secure memory initialization. |
|
| CVE-2026-25263 | Oct 06, 2026 |
Qualcomm IOCTL Kernel Memory CorruptionMemory corruption while processing IOCTL command called from user space to the kernel with invalid parameters. |
|
| CVE-2026-25265 | Sep 22, 2026 |
Priv Esc via Weak Temp File Handling in Qualcomm DevicePrivilege escalation due to weak configuration while temporary file handling. |
|
| CVE-2026-25264 | Sep 22, 2026 |
Qualcomm Android Priv Esc via Weak Config in Package ExtractionPrivilege escalation due to weak configuration during package extraction process. |
|
| CVE-2026-25262 | Sep 22, 2026 |
Qualcomm Primary Bootloader memory corruption via crafted ELF fileMemory corruption while processing a crafted ELF file in the Primary Bootloader. |
|
| CVE-2026-25255 | Sep 22, 2026 |
Qualcomm gRPC Server Privilege Escalation via Dangerous FunctionExposed dangerous function lead to privilege escalation via gRPC server. |
|
| CVE-2026-25254 | Sep 22, 2026 |
Qualcomm RCE via Improper Auth on SocketIOImproper authorization leads to Remote Code Execution via SocketIO interface. |
|
| CVE-2026-25294 | Sep 17, 2026 |
Qualcomm DOS via Transient Frame Parsing in Channel UsageTransient DOS while parsing frame during channel usage. |
|
| CVE-2026-25290 | Sep 17, 2026 |
Qualcomm buffer overflow via misused addition in length checkMemory Corruption when validating large data buffers from external sources using addition to check buffer length. |
|
| CVE-2026-25284 | Sep 17, 2026 |
Qualcomm UAF Pointer Reuse Info DisclosureInformation Disclosure when a pointer is reused after being deallocated. |
|
| CVE-2026-25283 | Sep 17, 2026 |
Qualcomm Buffer Overflow in External Data CopyMemory Corruption when copying unverified data from an external source exceeds the allocated buffer size. |
|
| CVE-2026-25282 | Sep 17, 2026 |
Qualcomm: Transient DOS via OOB Memory Access in Neighboring Data ProcessingTransient DOS when processing unverified data from a neighboring system causes out of bound memory access. |
|
| CVE-2026-25281 | Sep 17, 2026 |
Qualcomm Buffer Overflow Leads to Transient DoSTransient DOS when processing large or numerous request buffers without sufficient memory allocation validation. |
|
| CVE-2026-25280 | Sep 17, 2026 |
Qualcomm Escape Flow Buffer Overflow: Memory CorruptionMemory corruption when processing escape handling flow with insufficient user buffer sizes. |
|
| CVE-2026-25278 | Sep 17, 2026 |
Qualcomm I2C Driver MemCorruption Race ConditionMemory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying. |
|
| CVE-2026-25275 | Sep 17, 2026 |
Qualcomm WLAN Driver Transient DoS via Invalid FILS IE Header LengthTransient DOS when processing authentication frames with invalid FILS information element header lengths. |
|
| CVE-2026-25261 | Sep 17, 2026 |
CVE-2026-25261: Memory Corruption in Qualcomm Rear Sensor IOCTLMemory corruption while processing rear sensor IOCTL calls. |
|
| CVE-2026-24081 | Sep 17, 2026 |
Qualcomm Bluetooth Transient DOS via Insufficient Channel Map with AFH EnabledTransient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. |
|
| CVE-2026-24075 | Sep 17, 2026 |
Qualcomm IOCTL Race Causes Memory Corruption in Kernel DriverMemory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions. |
|
| CVE-2026-24074 | Sep 17, 2026 |
Qualcomm Data Copy Buffer Overflow in Handling Large OffsetsMemory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations. |
|
| CVE-2026-24073 | Sep 17, 2026 |
Memory corruption in Qualcomm Snapdragon Media Codec decode statsMemory corruption when processing decode statistics due to insufficient validation of offset against structure size. |
|
| CVE-2025-59607 | Sep 17, 2026 |
Qualcomm Memory Corruption via Large Input Over-AllocationMemory Corruption when copying large input data exceeds normal allocation limits. |
|
| CVE-2026-25292 | Aug 04, 2026 |
Memory Corruption in QCOM Fastboot Audio FrameworkMemory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. |
|
| CVE-2026-25289 | Aug 04, 2026 |
Qualcomm Wi-Fi Driver Memory Corruption via Invalid NAN Frame LengthMemory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. |
|
| CVE-2026-25288 | Aug 04, 2026 |
Transient DOS: Short TWTA Frame Insufficient Packet - Qualcomm WiFi SubsystemTransient DOS when processing a short target wake time channel usage response frame with insufficient packet size. |
|
| CVE-2026-24084 | Aug 04, 2026 |
Qualcomm UE Config Weakness: Inconsistent Security Capabilities Replay AttacksWeak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. |
|
| CVE-2026-24083 | Aug 04, 2026 |
Memory Corruption in Qualcomm Snapdragon IOCTL Device DriverMemory Corruption while processing IOCTL device driver requests with invalid arguments. |
|
| CVE-2026-24080 | Aug 04, 2026 |
CVE-2026-24080: Memory Corruption via Malformed Params in QCOM FP TAMemory Corruption when handling malformed request parameters in the fingerprint TA. |
|
| CVE-2026-24079 | Aug 04, 2026 |
Qualcomm Crypto Fault in Reg Auth | Malformed Params CVE-2026-24079Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. |
|
| CVE-2026-24078 | Aug 04, 2026 |
Qualcomm NG-eCall IPSec Negotiation Info DisclosureInformation Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. |
|
| CVE-2026-24077 | Aug 04, 2026 |
Qualcomm Wi-Fi Driver INFO Disclosure via Bad Length FieldInformation Disclosure when processing wireless network channel switch information with improperly formatted length fields. |
|
| CVE-2026-24076 | Aug 04, 2026 |
Qualcomm Driver Mem Corruption via Bad Reg QueryMemory Corruption when processing registry values with incorrect types using a direct query method. |
|
| CVE-2026-21366 | Aug 04, 2026 |
Qualcomm Packet Processing Buffer Overflow: CVE-2026-21366Memory corruption while processing a packet with a size close to the maximum allowed value. |
|
| CVE-2026-25271 | Jul 06, 2026 |
Qualcomm Android Memory Corruption in Async Param HandlingMemory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use. |
|
| CVE-2026-25268 | Jul 06, 2026 |
Qualcomm Wi-Fi Firmware HT40 Layout Memory CorruptionMemory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. |
|
| CVE-2026-21384 | Jul 06, 2026 |
Qualcomm Modem Firmware Memcorrupt via Invalid Port IndexMemory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits. |
|
| CVE-2026-21383 | Jul 06, 2026 |
Qualcomm Static IV in AES-GCM Key Wrap Causes Crypto FlawCryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security. |
|