Qualcomm Snapdragon

28 known vulnerabilities in Qualcomm Snapdragon, 1 critical, 8 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-21385 CVSS 7.8 high · actively exploited Qualcomm Multiple Chipsets Memory Corruption Vulnerability
  • CVE-2025-21479 CVSS 8.6 high · actively exploited Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
  • CVE-2025-27038 CVSS 7.5 high · actively exploited Qualcomm Multiple Chipsets Use-After-Free Vulnerability
  • CVE-2025-21480 CVSS 8.6 high · actively exploited Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
  • CVE-2024-43047 CVSS 7.8 high · actively exploited Qualcomm Multiple Chipsets Use-After-Free Vulnerability
  • CVE-2023-33107 CVSS 7.8 high · actively exploited Qualcomm Multiple Chipsets Integer Overflow Vulnerability
  • CVE-2023-33106 CVSS 7.8 high · actively exploited Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability
  • CVE-2023-33063 CVSS 7.8 high · actively exploited Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Latest vulnerabilities

  • CVE-2026-25265 CVSS 8.8 high Privilege escalation due to weak configuration while temporary file handling.
  • CVE-2026-25264 CVSS 8.8 high Privilege escalation due to weak configuration during package extraction process.
  • CVE-2026-25262 CVSS 6.9 medium Memory corruption while processing a crafted ELF file in the Primary Bootloader.
  • CVE-2026-25255 CVSS 8.8 high Exposed dangerous function lead to privilege escalation via gRPC server.
  • CVE-2026-25254 CVSS 9.8 critical Improper authorization leads to Remote Code Execution via SocketIO interface.
  • CVE-2026-25294 CVSS 7.4 high Transient DOS while parsing frame during channel usage.
  • CVE-2026-25290 CVSS 7.8 high Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
  • CVE-2026-25284 CVSS 7.3 high Information Disclosure when a pointer is reused after being deallocated.
  • CVE-2026-25283 CVSS 8.8 high Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
  • CVE-2026-25282 CVSS 7.9 high Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
  • CVE-2026-25281 CVSS 7.4 high Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
  • CVE-2026-25280 CVSS 7.8 high Memory corruption when processing escape handling flow with insufficient user buffer sizes.
  • CVE-2026-25278 CVSS 7.0 high Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
  • CVE-2026-25275 CVSS 7.5 high Transient DOS when processing authentication frames with invalid FILS information element header lengths.
  • CVE-2026-25261 CVSS 7.8 high Memory corruption while processing rear sensor IOCTL calls.
  • CVE-2026-24081 CVSS 7.4 high Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
  • CVE-2026-24075 CVSS 7.0 high Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and…
  • CVE-2026-24074 CVSS 7.8 high Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
  • CVE-2026-24073 CVSS 7.8 high Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
  • CVE-2025-59607 CVSS 7.8 high Memory Corruption when copying large input data exceeds normal allocation limits.
  • CVE-2026-21385 CVSS 7.8 high · actively exploited Qualcomm Multiple Chipsets Memory Corruption Vulnerability
  • CVE-2025-21479 CVSS 8.6 high · actively exploited Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
  • CVE-2025-27038 CVSS 7.5 high · actively exploited Qualcomm Multiple Chipsets Use-After-Free Vulnerability
  • CVE-2025-21480 CVSS 8.6 high · actively exploited Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
  • CVE-2024-43047 CVSS 7.8 high · actively exploited Qualcomm Multiple Chipsets Use-After-Free Vulnerability
  • CVE-2023-33107 CVSS 7.8 high · actively exploited Qualcomm Multiple Chipsets Integer Overflow Vulnerability
  • CVE-2023-33106 CVSS 7.8 high · actively exploited Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability
  • CVE-2023-33063 CVSS 7.8 high · actively exploited Qualcomm Multiple Chipsets Use-After-Free Vulnerability