Qualcomm, Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with Snapdragon.
Products
Clear product- Snapdragon962 vulnerabilities
- Android for MSM, Firefox OS for MSM, QRD Android306 vulnerabilities
- All Qualcomm products194 vulnerabilities
- Snapdragon Mobile, Snapdragon Wear132 vulnerabilities
- Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear123 vulnerabilities
- Snapdragon Mobile114 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables73 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables50 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking47 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables45 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables41 vulnerabilities
- Snapdragon Automobile, Snapdragon Mobile39 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking33 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables33 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking28 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking22 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables22 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile22 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking21 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile20 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking18 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables17 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking15 vulnerabilities
- Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music15 vulnerabilities
- Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking14 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-25292HIGH | Improper Validation of Syntactic Correctness of Input in Automotive Linux OSMemory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. CWE-1286Aug 4, 2026 | CVSS7.6v3.1 | EPSS0.102% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25289CRITICAL | Stack-based Buffer Overflow in WLAN FirmwareMemory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. CWE-121Aug 4, 2026 | CVSS9.6v3.1 | EPSS0.116% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25288HIGH | Buffer Over-read in WLAN FirmwareTransient DOS when processing a short target wake time channel usage response frame with insufficient packet size. CWE-126Aug 4, 2026 | CVSS7.4v3.1 | EPSS0.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24084HIGH | Insecure Security Identifier Mechanism in Multi-Mode Call ProcessorWeak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. CWE-1294Aug 4, 2026 | CVSS7.5v3.1 | EPSS0.148% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24083HIGH | Untrusted Pointer Dereference in Automotive SecurityMemory Corruption while processing IOCTL device driver requests with invalid arguments. CWE-822Aug 4, 2026 | CVSS7.8v3.1 | EPSS0.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24080HIGH | Buffer Copy Without Checking Size of Input in BiometricsMemory Corruption when handling malformed request parameters in the fingerprint TA. CWE-120Aug 4, 2026 | CVSS7.8v3.1 | EPSS0.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24079HIGH | Missing Authentication for Critical Function in Data ModemCryptographic Issue while processing registration requests with malformed or missing authentication parameters. CWE-306Aug 4, 2026 | CVSS8.1v3.1 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24078MEDIUM | Exposure of Private Personal Information to an Unauthorized Actor in Data ModemInformation Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. CWE-359Aug 4, 2026 | CVSS6.5v3.1 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24077MEDIUM | Integer Underflow (Wrap or Wraparound) in WLAN HostInformation Disclosure when processing wireless network channel switch information with improperly formatted length fields. CWE-191Aug 4, 2026 | CVSS6.5v3.1 | EPSS0.106% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24076MEDIUM | Buffer Copy Without Checking Size of Input in Bluetooth HOSTMemory Corruption when processing registry values with incorrect types using a direct query method. CWE-120Aug 4, 2026 | CVSS6.7v3.1 | EPSS0.073% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21366HIGH | Integer Overflow or Wraparound in Data Network Stack & ConnectivityMemory corruption while processing a packet with a size close to the maximum allowed value. CWE-190Aug 4, 2026 | CVSS7.8v3.1 | EPSS0.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25271HIGH | Time-of-check Time-of-use (TOCTOU) Race Condition in DSP ServiceMemory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use. CWE-367Jul 6, 2026 | CVSS7.8v3.1 | EPSS0.052% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25268HIGH | Stack-based Buffer Overflow in WLAN HostMemory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. CWE-121Jul 6, 2026 | CVSS8.8v3.1 | EPSS0.072% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21384MEDIUM | Out-of-bounds Write in Camera DriverMemory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits. CWE-787Jul 6, 2026 | CVSS5.3v3.1 | EPSS0.056% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21383HIGH | Reusing a Nonce, Key Pair in Encryption in HLOSCryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security. CWE-323Jul 6, 2026 | CVSS7.1v3.1 | EPSS0.069% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21379HIGH | Buffer Over-read in Windows ComputeMemory Corruption when allocating memory with sizes that exceed the maximum allowed value. CWE-126Jul 6, 2026 | CVSS7.8v3.1 | EPSS0.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21370MEDIUM | Out-of-bounds Write in Camera DriverMemory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values. CWE-787Jul 6, 2026 | CVSS5.3v3.1 | EPSS0.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21369MEDIUM | Out-of-bounds Write in Camera DriverMemory Corruption when handling flash commands due to outdated LED count values being used after userspace modification. CWE-787Jul 6, 2026 | CVSS5.3v3.1 | EPSS0.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21368MEDIUM | Out-of-bounds Write in Camera DriverMemory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks. CWE-787Jul 6, 2026 | CVSS5.3v3.1 | EPSS0.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59617MEDIUM | Use After Free in Computer VisionMemory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input. CWE-416Jul 6, 2026 | CVSS6.6v3.1 | EPSS0.065% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59616MEDIUM | Use After Free in Computer VisionMemory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory. CWE-416Jul 6, 2026 | CVSS6.6v3.1 | EPSS0.064% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59615MEDIUM | Use After Free in Computer VisionMemory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization. CWE-416Jul 6, 2026 | CVSS6.6v3.1 | EPSS0.064% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25277HIGH | Buffer Copy Without Checking Size of Input in Secure ProcessorMemory corruption while using Strongbox due to buffer overflow. CWE-120Jun 1, 2026 | CVSS8.8v3.1 | EPSS0.074% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25276HIGH | Improper Validation of Array Index in Secure ProcessorMemory corruption while using Strongbox due to missing bounds check. CWE-129Jun 1, 2026 | CVSS8.8v3.1 | EPSS0.075% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25260HIGH | Time-of-check Time-of-use (TOCTOU) Race Condition in DSP ServiceMemory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications. CWE-367Jun 1, 2026 | CVSS7.8v3.1 | EPSS0.052% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |