Qualcomm
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Qualcomm product.
RSS Feeds for Qualcomm security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Qualcomm products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Qualcomm Sorted by Most Security Vulnerabilities since 2018
Known Exploited Qualcomm Vulnerabilities
The following Qualcomm vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Qualcomm Multiple Chipsets Memory Corruption Vulnerability |
Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. CVE-2026-21385 Exploit Probability: 0.2% |
March 3, 2026 |
| Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability |
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. CVE-2025-21479 Exploit Probability: 0.2% |
June 3, 2025 |
| Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability |
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. CVE-2025-21480 Exploit Probability: 2.0% |
June 3, 2025 |
| Qualcomm Multiple Chipsets Use-After-Free Vulnerability |
Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome. CVE-2025-27038 Exploit Probability: 1.4% |
June 3, 2025 |
| Qualcomm Multiple Chipsets Use-After-Free Vulnerability |
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory. CVE-2024-43047 Exploit Probability: 1.7% |
October 8, 2024 |
| Qualcomm Multiple Chipsets Integer Overflow Vulnerability |
Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. CVE-2023-33107 Exploit Probability: 0.4% |
December 5, 2023 |
| Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability |
Multiple Qualcomm chipsets contain a use of out-of-range pointer offset vulnerability due to memory corruption in Graphics while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. CVE-2023-33106 Exploit Probability: 0.2% |
December 5, 2023 |
| Qualcomm Multiple Chipsets Use-After-Free Vulnerability |
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services during a remote call from HLOS to DSP. CVE-2023-33063 Exploit Probability: 0.4% |
December 5, 2023 |
| Qualcomm Multiple Chipsets Use-After-Free Vulnerability |
Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL munmap call and process initialization is in progress. CVE-2022-22071 Exploit Probability: 0.6% |
December 5, 2023 |
| Qualcomm Multiple Chipsets Improper Input Validation Vulnerability |
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables CVE-2020-11261 Exploit Probability: 0.8% |
December 1, 2021 |
| Qualcomm Improper Error Handling Vulnerability |
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. CVE-2021-1906 Exploit Probability: 0.1% |
November 3, 2021 |
| Qualcomm Use-After-Free Vulnerability |
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously CVE-2021-1905 Exploit Probability: 0.8% |
November 3, 2021 |
By the Year
In 2026 there have been 95 vulnerabilities in Qualcomm with an average score of 7.4 out of ten. Last year, in 2025 Qualcomm had 122 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Qualcomm in 2026 could surpass last years number. Last year, the average CVE base score was greater by 0.26
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 95 | 7.37 |
| 2025 | 122 | 7.63 |
| 2024 | 6 | 7.82 |
| 2023 | 9 | 8.22 |
| 2022 | 52 | 7.58 |
| 2021 | 227 | 7.67 |
| 2020 | 170 | 7.10 |
| 2019 | 150 | 9.80 |
| 2018 | 227 | 0.00 |
It may take a day or so for new Qualcomm vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Qualcomm Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-25277 | Jun 01, 2026 |
Qualcomm Strongbox TEE Buffer Overflow Memory CorruptionMemory corruption while using Strongbox due to buffer overflow. |
|
| CVE-2026-25276 | Jun 01, 2026 |
CVE-2026-25276: Memory Corruption in Qualcomm Strongbox (Bound Check Missing)Memory corruption while using Strongbox due to missing bounds check. |
|
| CVE-2026-25260 | Jun 01, 2026 |
Qualcomm Memory Corruption in Shared Buffer Access (CVE-2026-25260)Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications. |
|
| CVE-2026-25259 | Jun 01, 2026 |
Memory corruption in Qualcomm QMI Modem IOCTL escape opsMemory corruption while processing multiple IOCTL command for escape operations. |
|
| CVE-2026-25258 | Jun 01, 2026 |
Memory Corruption in Qualcomm IOCTL Escape HandlerMemory corruption while processing IOCTL calls for escape operations. |
|
| CVE-2026-24092 | Jun 01, 2026 |
Qualcomm Fastboot Memory Corruption on DisplayMode SetMemory Corruption when processing fastboot commands to set display mode. |
|
| CVE-2026-24091 | Jun 01, 2026 |
Qualcomm Fastboot Memory Corrupt via Malformed InputMemory corruption while processing fastboot commands with improperly formatted input. |
|
| CVE-2026-24090 | Jun 01, 2026 |
Qualcomm Bootloader Crypto Flaw Lets Unauthorized Boot Flow ChangeCryptographic issue while processing partition table entries allows unauthorized modification of boot flow. |
|
| CVE-2026-24089 | Jun 01, 2026 |
CVE-2026-24089: Memory Corruption in Fastboot CommandsMemory corruption while processing fastboot commands with invalid input. |
|
| CVE-2026-24088 | Jun 01, 2026 |
Unauthorized Write via Crypto Defect in Qualcomm Partition Handler (BL)Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. |
|
| CVE-2026-24087 | Jun 01, 2026 |
Memory corruption in Qualcomm Fastboot OEM commandsMemory corruption while processing fastboot OEM commands. |
|
| CVE-2026-24085 | Jun 01, 2026 |
Qualcomm Snapdragon Memory Corruption via Uninitialized Variable in Display CLIMemory Corruption when processing display command line information due to improper initialization of a variable. |
|
| CVE-2025-59614 | Jun 01, 2026 |
Qualcomm RNG Driver Buffer Overflow Memory CorruptionMemory Corruption when sending random number generator command with insufficient output buffer size. |
|
| CVE-2025-59613 | Jun 01, 2026 |
Qualcomm Buffer Overflow via Small Output Buffer in Data CopyMemory Corruption when output buffer size is smaller than input buffer size during data copying operation. |
|
| CVE-2025-59612 | Jun 01, 2026 |
Memory Corruption in Qualcomm Windows Drivers via Invalid Trusted App RequestMemory corruption in windows drivers while sending incorrect trusted application request |
|
| CVE-2025-59611 | Jun 01, 2026 |
Memory Corruption in Qualcomm Diagnostic Services via Input Validation FailureMemory corruption in diagnostic services due to absence of input validation |
|
| CVE-2025-59610 | Jun 01, 2026 |
CVE-2025-59610: IOCTL Memory Corruption in Qualcomm Snapdragon DriverMemory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. |
|
| CVE-2025-59609 | Jun 01, 2026 |
Info Disclosure via Short MBSSID in Qualcomm BluetoothInformation Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. |
|
| CVE-2025-59606 | Jun 01, 2026 |
Qualcomm QSEE Memory Corruption via Heap Overflow in Secure Data InitMemory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization. |
|
| CVE-2025-59605 | Jun 01, 2026 |
Qualcomm driver memory corruption via overlength device IDMemory Corruption when processing device identifier strings that exceed the expected maximum length. |
|
| CVE-2025-59604 | Jun 01, 2026 |
Qualcomm Memory Corruption via Null Ptr on memcpyMemory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. |
|
| CVE-2025-59601 | Jun 01, 2026 |
Qualcomm Powerline Info Disclosure on Factory ResetInformation Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration. |
|
| CVE-2026-25293 | May 04, 2026 |
PLC FW Assigner Buffer Overflow due to Wrong Auth (Qualcomm)Buffer overflow due to incorrect authorization in PLC FW |
|
| CVE-2026-25266 | May 04, 2026 |
Qualcomm IOCTL Memory Corruption in Power-Save ModeMemory corruption while processing IOCTL command when device is in power-save state. |
|
| CVE-2026-24082 | May 04, 2026 |
Memory Corruption in Qualcomm Snapdragon Perf Counter Driver During DeselectMemory Corruption when copying data from a freed source while executing performance counter deselect operation. |
|
| CVE-2025-47408 | May 04, 2026 |
Qualcomm Driver IOCTL Buffer Corruption VulnerabilityMemory corruption when another driver calls an IOCTL with invalid input/output buffer. |
|
| CVE-2025-47407 | May 04, 2026 |
Memory Corruption in Qualcomm DSP Process Creation due to Allocation FailureMemory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level. |
|
| CVE-2025-47406 | May 04, 2026 |
CVE-2025-47406: Qualcomm IOCTL Buffer Size OOB DisclosureInformation Disclosure while processing IOCTL handler callbacks without verifying buffer size. |
|
| CVE-2025-47405 | May 04, 2026 |
Qualcomm Camera Driver Buffer Overflow via Invalid Output BuffersMemory corruption when processing camera sensor input/output control codes with invalid output buffers. |
|
| CVE-2025-47404 | May 04, 2026 |
Qualcomm Snapdragon Driver Buffer Resize Memory CorruptionMemory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. |
|
| CVE-2025-47403 | May 04, 2026 |
Qualcomm Wireless Driver DOS via Malformed FT FrameTransient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. |
|
| CVE-2025-47401 | May 04, 2026 |
Qualcomm Target Power Rate Table Channel Config DoSTransient DOS when processing target power rate tables during channel configuration. |
|
| CVE-2026-21382 | Apr 06, 2026 |
Memory Corruption via Improper Buffer Sizing in Qualcomm PMMemory Corruption when handling power management requests with improperly sized input/output buffers. |
|
| CVE-2026-21381 | Apr 06, 2026 |
Qualcomm QCA WiFi NAN DoS via Excessive Service Data Frame LengthTransient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. |
|
| CVE-2026-21380 | Apr 06, 2026 |
Qualcomm DMABUF IOCTL Memory CorruptionMemory Corruption when using deprecated DMABUF IOCTL calls to manage video memory. |
|
| CVE-2026-21378 | Apr 06, 2026 |
Qualcomm Camera Driver Output Buffer Size Validation BypassMemory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. |
|
| CVE-2026-21376 | Apr 06, 2026 |
Qualcomm Camera Sensor Driver IOCTL Buffer Validation FlawMemory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. |
|
| CVE-2026-21375 | Apr 06, 2026 |
Qualcomm IOCTL Output Buffer Size Bypass Causing Mem CorruptionMemory Corruption when accessing an output buffer without validating its size during IOCTL processing. |
|
| CVE-2026-21374 | Apr 06, 2026 |
Memory Corruption in Qualcomm Sensor Driver Aux IO Ctl CMD Buffer OverflowMemory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation. |
|
| CVE-2026-21373 | Apr 06, 2026 |
Qualcomm Kernel Driver Output Buffer Size Validation FlawMemory Corruption when accessing an output buffer without validating its size during IOCTL processing. |
|
| CVE-2026-21372 | Apr 06, 2026 |
Qualcomm IOCTL Buffer Overrun via memcpy (CVE-2026-21372)Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations. |
|
| CVE-2026-21371 | Apr 06, 2026 |
Qualcomm Android Kernel: Buffer Size Validation Causes Memory CorruptionMemory Corruption when retrieving output buffer with insufficient size validation. |
|
| CVE-2026-21367 | Apr 06, 2026 |
Qualcomm WiFi 6 FW DOS via out-of-range FILS Discovery FramesTransient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. |
|
| CVE-2025-47400 | Apr 06, 2026 |
Qualcomm Crypto Lib Buffer Overflow During Data Copy CVE-2025-47400Cryptographic issue while copying data to a destination buffer without validating its size. |
|
| CVE-2025-47392 | Apr 06, 2026 |
Qualcomm Satellite Decoder MemCorrupt on Invalid Sign OffsetsMemory corruption when decoding corrupted satellite data files with invalid signature offsets. |
|
| CVE-2025-47391 | Apr 06, 2026 |
Qualcomm Snapdragon: Mem Corruption in Frame Request HandlingMemory corruption while processing a frame request from user. |
|
| CVE-2025-47390 | Apr 06, 2026 |
Qualcomm JPEG Driver IOCTL Memory CorruptionMemory corruption while preprocessing IOCTL request in JPEG driver. |
|
| CVE-2025-47389 | Apr 06, 2026 |
Qualcomm QSEE Buffer Overflow in Attestation Report GenerationMemory corruption when buffer copy operation fails due to integer overflow during attestation report generation. |
|
| CVE-2025-47374 | Apr 06, 2026 |
Qualcomm Adreno GPU Memory Fault via Fence Dereg & SignalMemory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling. |
|
| CVE-2026-21385 | Mar 02, 2026 |
Qualcomm Memory Corruption via Alignment AllocationMemory corruption while using alignments for memory allocation. |
|