« Back to list

Qualcomm

Qualcomm Sm4635 Firmware: vulnerabilities and CVEs

Qualcomm Sm4635 Firmware has 77 published vulnerabilities, 17 of them in the last 12 months. 3 are rated critical and 2 are listed by CISA as actively exploited.

CVEs77
Last 12 months17
Critical3
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-21480High (8.6)0.46%⚠ Active exploitationJun 3, 2025
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVE-2025-21479High (8.6)0.84%⚠ Active exploitationJun 3, 2025
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-47366High (7.8)0.10%—Feb 2, 2026
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
CVE-2025-47348High (7.8)0.08%—Jan 7, 2026
Memory corruption while processing identity credential operations in the trusted application.
CVE-2025-47346High (7.8)0.08%—Jan 7, 2026
Memory corruption while processing a secure logging command in the trusted application.
CVE-2025-47345High (8.4)0.08%—Jan 7, 2026
Cryptographic issue may occur while encrypting license data.
CVE-2025-47344Medium (6.4)0.06%—Jan 7, 2026
Memory corruption while handling sensor utility operations.
CVE-2025-47339High (7.8)0.08%—Jan 7, 2026
Memory corruption while deinitializing a HDCP session.
CVE-2025-47334Medium (6.7)0.08%—Jan 7, 2026
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
CVE-2025-47333Medium (6.6)0.08%—Jan 7, 2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
CVE-2025-47331Medium (6.1)0.08%—Jan 7, 2026
Information disclosure while processing a firmware event.
CVE-2025-47330Medium (5.5)0.07%—Jan 7, 2026
Transient DOS while parsing video packets received from the video firmware.
CVE-2025-47382High (7.8)0.09%—Dec 18, 2025
Memory corruption while loading an invalid firmware in boot loader.
CVE-2025-47320High (7.8)0.08%—Dec 18, 2025
Memory corruption while processing MFC channel configuration during music playback.
CVE-2025-47319Medium (6.7)0.09%—Dec 18, 2025
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
CVE-2025-47323High (7.8)0.09%—Dec 18, 2025
Memory corruption while routing GPR packets between user and root when handling large data packet.
CVE-2025-27070High (7.8)0.06%—Nov 4, 2025
Memory corruption while performing encryption and decryption commands.
CVE-2025-27054High (7.8)0.09%—Oct 9, 2025
Memory corruption while processing a malformed license file during reboot.
CVE-2025-27053High (7.8)0.09%—Oct 9, 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-27034Critical (9.8)0.40%—Sep 24, 2025
Memory corruption while selecting the PLMN from SOR failed list.
CVE-2025-21483Critical (9.8)0.40%—Sep 24, 2025
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-21481High (7.8)0.07%—Sep 24, 2025
Memory corruption while performing private key encryption in trusted application.
CVE-2025-21488High (8.2)0.27%—Sep 24, 2025
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
CVE-2025-21487High (8.2)0.26%—Sep 24, 2025
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
CVE-2025-21482High (7.1)0.08%—Sep 24, 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-27066High (7.5)0.28%—Aug 6, 2025
Transient DOS while processing an ANQP message.
CVE-2025-21465Medium (6.5)0.09%—Aug 6, 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Medium (6.5)0.09%—Aug 6, 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2025-27061High (7.8)0.09%—Jul 8, 2025
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVE-2025-27052High (7.8)0.09%—Jul 8, 2025
Memory corruption while processing data packets in diag received from Unix clients.
CVE-2025-27043High (7.8)0.09%—Jul 8, 2025
Memory corruption while processing manipulated payload in video firmware.
CVE-2025-27042High (7.8)0.09%—Jul 8, 2025
Memory corruption while processing video packets received from video firmware.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation36
  2. T1059 Command and Scripting Interpreter31
  3. T1190 Exploit Public-Facing Application15
  4. T1005 Data from Local System9
  5. T1499.004 Application or System Exploitation3
  6. T1078 Valid Accounts2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm