« Back to list

Qualcomm

Qualcomm Sd855 Firmware: vulnerabilities and CVEs

Qualcomm Sd855 Firmware has 600 published vulnerabilities, 5 of them in the last 12 months. 79 are rated critical and 8 are listed by CISA as actively exploited.

CVEs600
Last 12 months5
Critical79
Actively exploited8

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-21480High (8.6)0.46%⚠ Active exploitationJun 3, 2025
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2025-21479High (8.6)0.84%⚠ Active exploitationJun 3, 2025
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2023-33107High (7.8)0.89%⚠ Active exploitationDec 5, 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
CVE-2022-22071High (7.8)0.46%⚠ Active exploitationJun 14, 2022
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…
CVE-2023-33063High (7.8)0.69%⚠ Active exploitationDec 5, 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2020-11261High (7.8)1.6%⚠ Active exploitationJun 9, 2021
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…
CVE-2021-1906Medium (5.5)0.52%⚠ Active exploitationMay 7, 2021
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-1905High (7.8)1.5%⚠ Active exploitationMay 7, 2021
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-47348High (7.8)0.08%—Jan 7, 2026
Memory corruption while processing identity credential operations in the trusted application.
CVE-2025-47333Medium (6.6)0.08%—Jan 7, 2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
CVE-2025-47320High (7.8)0.08%—Dec 18, 2025
Memory corruption while processing MFC channel configuration during music playback.
CVE-2025-27054High (7.8)0.09%—Oct 9, 2025
Memory corruption while processing a malformed license file during reboot.
CVE-2025-27053High (7.8)0.09%—Oct 9, 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-27032High (7.8)0.08%—Sep 24, 2025
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
CVE-2025-21483Critical (9.8)0.40%—Sep 24, 2025
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-21481High (7.8)0.07%—Sep 24, 2025
Memory corruption while performing private key encryption in trusted application.
CVE-2025-21487High (8.2)0.26%—Sep 24, 2025
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
CVE-2025-21484High (8.2)0.26%—Sep 24, 2025
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
CVE-2025-21482High (7.1)0.08%—Sep 24, 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-27066High (7.5)0.28%—Aug 6, 2025
Transient DOS while processing an ANQP message.
CVE-2025-21465Medium (6.5)0.09%—Aug 6, 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Medium (6.5)0.09%—Aug 6, 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2025-21452High (7.5)0.21%—Aug 6, 2025
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
CVE-2025-27061High (7.8)0.09%—Jul 8, 2025
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVE-2025-27042High (7.8)0.09%—Jul 8, 2025
Memory corruption while processing video packets received from video firmware.
CVE-2025-21454High (7.5)0.22%—Jul 8, 2025
Transient DOS while processing received beacon frame.
CVE-2025-21449High (7.5)0.22%—Jul 8, 2025
Transient DOS may occur while processing malformed length field in SSID IEs.
CVE-2025-21433Medium (5.5)0.08%—Jul 8, 2025
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
CVE-2025-21432High (7.8)0.09%—Jul 8, 2025
Memory corruption while retrieving the CBOR data from TA.
CVE-2025-21427High (8.2)0.22%—Jul 8, 2025
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
CVE-2025-21422High (7.8)0.10%—Jul 8, 2025
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
CVE-2024-53009High (7.8)0.09%—Jul 8, 2025
Memory corruption while operating the mailbox in Automotive.
CVE-2025-21479High (8.6)0.84%⚠ Active exploitationJun 3, 2025
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2025-21480High (8.6)0.46%⚠ Active exploitationJun 3, 2025
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2024-53026High (8.2)0.30%—Jun 3, 2025
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2024-53021High (8.2)0.24%—Jun 3, 2025
Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2024-53020High (8.2)0.24%—Jun 3, 2025
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2024-53015Medium (6.6)0.09%—Jun 3, 2025
Memory corruption while processing IOCTL command to handle buffers associated with a session.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation27
  2. T1059 Command and Scripting Interpreter26
  3. T1190 Exploit Public-Facing Application13
  4. T1005 Data from Local System6
  5. T1499.004 Application or System Exploitation5
  6. T1203 Exploitation for Client Execution2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm