Qualcomm Snapdragon
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Qualcomm Snapdragon.
By the Year
In 2026 there have been 152 vulnerabilities in Qualcomm Snapdragon with an average score of 7.4 out of ten. Last year, in 2025 Snapdragon had 103 security vulnerabilities published. That is, 49 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.22
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 152 | 7.39 |
| 2025 | 103 | 7.61 |
| 2024 | 1 | 7.80 |
| 2023 | 6 | 8.23 |
| 2022 | 52 | 7.58 |
| 2021 | 227 | 7.67 |
| 2020 | 167 | 0.00 |
| 2019 | 147 | 0.00 |
| 2018 | 183 | 0.00 |
It may take a day or so for new Snapdragon vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Qualcomm Snapdragon Security Vulnerabilities
Memory corruption in Qualcomm service request processing
CVE-2026-57559
7.8 - High
- October 06, 2026
Memory corruption while processing service requests.
Dangling pointer
Qualcomm Memory Corruption in System Service Routines
CVE-2026-57555
7.8 - High
- October 06, 2026
Memory Corruption when executing system service routines due to improper handling of user input buffers.
Dangling pointer
Qualcomm FastRPC: Memory Corruption on Concurrent Perf Counter Access
CVE-2026-57554
7.8 - High
- October 06, 2026
Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations.
Dangling pointer
Qualcomm Modem Firmware DOS via Zero-Sized Config Override
CVE-2026-57546
7.5 - High
- October 06, 2026
Transient DOS when processing a continuous receive command with a zero-sized global configuration override.
Buffer Over-read
Qualcomm GPU Driver: Memory Corruption via Draw Object Inconsistency
CVE-2026-57545
7.8 - High
- October 06, 2026
Memory corruption when processing draw objects of incorrect type during graphics command list execution.
Untrusted Pointer Dereference
Memory Corruption in Qualcomm Mapping SDK via Concurrent Access
CVE-2026-57537
7.8 - High
- October 06, 2026
Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization.
Dangling pointer
Qualcomm: Auth Bypass for Unsigned Images on Non-ELF Partitions
CVE-2026-25302
7.1 - High
- October 06, 2026
Cryptographic Issue when processing non-ELF partitions, authentication and signature checks are bypassed, allowing unsigned or corrupted images to be mounted and processed.
Improper Verification of Cryptographic Signature
Qualcomm Memory corruption in shared memory page lists (CVE-2026-25291)
CVE-2026-25291
7.8 - High
- October 06, 2026
Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms.
Dangling pointer
Qualcomm Snapdragon SoC Memory Corruption via Un-Sync DMA Buffer
CVE-2026-25274
6.7 - Medium
- October 06, 2026
Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization.
Dangling pointer
Qualcomm Camera Driver OOB Write CVE-2026-25273
CVE-2026-25273
6.7 - Medium
- October 06, 2026
Memory Corruption when processing camera operations due to out-of-bounds write during driver updates.
Memory Corruption
Memory Corruption in Qualcomm Camera CRE Driver via Buffer Overflow during HW Update
CVE-2026-25272
6.7 - Medium
- October 06, 2026
Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation.
Memory Corruption
Android Camera Driver Memory Corruption via Invalid CmdBuffer Length
CVE-2026-25270
6.7 - Medium
- October 06, 2026
Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver.
Memory Corruption
Qualcomm Camera Driver Memory Corruption via Excessive Batch/IO Buffer Config
CVE-2026-25269
6.7 - Medium
- October 06, 2026
Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size.
Memory Corruption
Qualcomm Secure Bootloader Mem Corruption via Page Table Rewrite
CVE-2026-25267
7.8 - High
- October 06, 2026
Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
AuthZ
Qualcomm IOCTL Kernel Memory Corruption
CVE-2026-25263
6.6 - Medium
- October 06, 2026
Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters.
Memory Corruption
Priv Esc via Weak Temp File Handling in Qualcomm Device
CVE-2026-25265
8.8 - High
- September 22, 2026
Privilege escalation due to weak configuration while temporary file handling.
Creation of Temporary File With Insecure Permissions
Qualcomm Android Priv Esc via Weak Config in Package Extraction
CVE-2026-25264
8.8 - High
- September 22, 2026
Privilege escalation due to weak configuration during package extraction process.
DLL preloading
Qualcomm Primary Bootloader memory corruption via crafted ELF file
CVE-2026-25262
6.9 - Medium
- September 22, 2026
Memory corruption while processing a crafted ELF file in the Primary Bootloader.
Write-what-where Condition
Qualcomm gRPC Server Privilege Escalation via Dangerous Function
CVE-2026-25255
8.8 - High
- September 22, 2026
Exposed dangerous function lead to privilege escalation via gRPC server.
Exposed Dangerous Method or Function
Qualcomm RCE via Improper Auth on SocketIO
CVE-2026-25254
9.8 - Critical
- September 22, 2026
Improper authorization leads to Remote Code Execution via SocketIO interface.
AuthZ
Qualcomm DOS via Transient Frame Parsing in Channel Usage
CVE-2026-25294
7.4 - High
- September 17, 2026
Transient DOS while parsing frame during channel usage.
Buffer Over-read
Qualcomm buffer overflow via misused addition in length check
CVE-2026-25290
7.8 - High
- September 17, 2026
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
Integer Overflow or Wraparound
Qualcomm UAF Pointer Reuse Info Disclosure
CVE-2026-25284
7.3 - High
- September 17, 2026
Information Disclosure when a pointer is reused after being deallocated.
Buffer Over-read
Qualcomm Buffer Overflow in External Data Copy
CVE-2026-25283
8.8 - High
- September 17, 2026
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
Stack Overflow
Qualcomm: Transient DOS via OOB Memory Access in Neighboring Data Processing
CVE-2026-25282
7.9 - High
- September 17, 2026
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
Out-of-bounds Read
Qualcomm Buffer Overflow Leads to Transient DoS
CVE-2026-25281
7.4 - High
- September 17, 2026
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
Allocation of Resources Without Limits or Throttling
Qualcomm Escape Flow Buffer Overflow: Memory Corruption
CVE-2026-25280
7.8 - High
- September 17, 2026
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
Memory Corruption
Qualcomm I2C Driver MemCorruption Race Condition
CVE-2026-25278
7.8 - High
- September 17, 2026
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
TOCTTOU
Qualcomm WLAN Driver Transient DoS via Invalid FILS IE Header Length
CVE-2026-25275
7.5 - High
- September 17, 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Buffer Over-read
CVE-2026-25261: Memory Corruption in Qualcomm Rear Sensor IOCTL
CVE-2026-25261
6.7 - Medium
- September 17, 2026
Memory corruption while processing rear sensor IOCTL calls.
Untrusted Pointer Dereference
Qualcomm Bluetooth Transient DOS via Insufficient Channel Map with AFH Enabled
CVE-2026-24081
7.4 - High
- September 17, 2026
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
Buffer Over-read
Qualcomm IOCTL Race Causes Memory Corruption in Kernel Driver
CVE-2026-24075
7.8 - High
- September 17, 2026
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
Buffer Over-read
Qualcomm Data Copy Buffer Overflow in Handling Large Offsets
CVE-2026-24074
7.8 - High
- September 17, 2026
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
Memory Corruption
Memory corruption in Qualcomm Snapdragon Media Codec decode stats
CVE-2026-24073
7.8 - High
- September 17, 2026
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
Memory Corruption
Qualcomm Memory Corruption via Large Input Over-Allocation
CVE-2025-59607
7.8 - High
- September 17, 2026
Memory Corruption when copying large input data exceeds normal allocation limits.
Untrusted Pointer Dereference
Memory Corruption in QCOM Fastboot Audio Framework
CVE-2026-25292
7.6 - High
- August 04, 2026
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
Improper Validation of Syntactic Correctness of Input
Qualcomm Wi-Fi Driver Memory Corruption via Invalid NAN Frame Length
CVE-2026-25289
9.6 - Critical
- August 04, 2026
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
Stack Overflow
Transient DOS: Short TWTA Frame Insufficient Packet - Qualcomm WiFi Subsystem
CVE-2026-25288
7.4 - High
- August 04, 2026
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
Buffer Over-read
Qualcomm UE Config Weakness: Inconsistent Security Capabilities Replay Attacks
CVE-2026-24084
7.5 - High
- August 04, 2026
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
Insecure Security Identifier Mechanism
Memory Corruption in Qualcomm Snapdragon IOCTL Device Driver
CVE-2026-24083
7.8 - High
- August 04, 2026
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
Untrusted Pointer Dereference
CVE-2026-24080: Memory Corruption via Malformed Params in QCOM FP TA
CVE-2026-24080
7.8 - High
- August 04, 2026
Memory Corruption when handling malformed request parameters in the fingerprint TA.
Classic Buffer Overflow
Qualcomm Crypto Fault in Reg Auth | Malformed Params CVE-2026-24079
CVE-2026-24079
8.1 - High
- August 04, 2026
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
Missing Authentication for Critical Function
Qualcomm NG-eCall IPSec Negotiation Info Disclosure
CVE-2026-24078
6.5 - Medium
- August 04, 2026
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
Privacy violation
Qualcomm Wi-Fi Driver INFO Disclosure via Bad Length Field
CVE-2026-24077
6.5 - Medium
- August 04, 2026
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
Integer underflow
Qualcomm Driver Mem Corruption via Bad Reg Query
CVE-2026-24076
6.7 - Medium
- August 04, 2026
Memory Corruption when processing registry values with incorrect types using a direct query method.
Classic Buffer Overflow
Qualcomm Packet Processing Buffer Overflow: CVE-2026-21366
CVE-2026-21366
7.8 - High
- August 04, 2026
Memory corruption while processing a packet with a size close to the maximum allowed value.
Integer Overflow or Wraparound
Qualcomm Android Memory Corruption in Async Param Handling
CVE-2026-25271
7.8 - High
- July 06, 2026
Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.
TOCTTOU
Qualcomm Wi-Fi Firmware HT40 Layout Memory Corruption
CVE-2026-25268
8.8 - High
- July 06, 2026
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
Stack Overflow
Qualcomm Modem Firmware Memcorrupt via Invalid Port Index
CVE-2026-21384
5.3 - Medium
- July 06, 2026
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
Memory Corruption
Qualcomm Static IV in AES-GCM Key Wrap Causes Crypto Flaw
CVE-2026-21383
7.1 - High
- July 06, 2026
Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.
Reusing a Nonce, Key Pair in Encryption
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Qualcomm Snapdragon or by Qualcomm? Click the Watch button to subscribe.