Skip to main content

Recently Exploited Qualcomm CVEs

Affected Products

3 products
ProductCVEsKEVLatest
Multiple Chipsets10102026-03-03
Multiple Chipsets 112024-10-08
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables112021-12-01

Security Advisories

Qualcomm Product Security Bulletins
https://docs.qualcomm.com/product/publicresources/securitybulletin/

Weakness Types

All Qualcomm CVEs

12 records
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-21385
Integer Overflow or Wraparound in Graphics
Qualcomm, Inc.7.81.3%KEV2026-03-02
CVE-2025-27038
Use After Free in Graphics
Qualcomm, Inc.7.51.0%KEV2025-06-03
CVE-2025-21479
Incorrect Authorization in Graphics
Qualcomm, Inc.8.60.8%KEV2025-06-03
CVE-2025-21480
Incorrect Authorization in Graphics Windows
Qualcomm, Inc.8.60.5%KEV2025-06-03
CVE-2024-43047
Use After Free in DSP Service
Qualcomm, Inc.7.80.7%KEV2024-10-07
CVE-2023-33106
Use of Out-of-range Pointer Offset in Graphics
Qualcomm, Inc.8.40.8%KEV2023-12-05
CVE-2023-33107
Integer Overflow or Wraparound in Graphics Linux
Qualcomm, Inc.8.40.7%KEV2023-12-05
CVE-2023-33063
Use After Free in DSP Services
Qualcomm, Inc.7.80.7%KEV2023-12-05
CVE-2022-22071
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Qualcomm, Inc.8.40.4%KEV2022-06-14
CVE-2020-11261
Qualcomm Multiple Chipsets Improper Input Validation Vulnerability
Qualcomm, Inc.7.81.6%KEV2021-06-09
CVE-2021-1905
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Qualcomm, Inc.8.41.5%KEV2021-05-07
CVE-2021-1906
Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability
Qualcomm, Inc.6.20.5%KEV2021-05-07

Frequently Asked Questions

How many Qualcomm vulnerabilities are actively exploited?→

12 Qualcomm CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-03-03.

Which Qualcomm products have the most exploited vulnerabilities?→
  • +Multiple Chipsets: 10 CVEs (10 in KEV)
  • +Multiple Chipsets : 1 CVE (1 in KEV)
  • +Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables: 1 CVE (1 in KEV)
Where does Qualcomm publish security advisories?→

Qualcomm publishes security advisories at https://docs.qualcomm.com/product/publicresources/securitybulletin/. Check the vendor advisory for fixed versions and workarounds before applying updates.

Sources

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Qualcomm, MITRE, CISA, or FIRST.