« Volver al listado

Qualcomm

Qualcomm Snapdragon 626 Mobile Platform Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon 626 Mobile Platform Firmware tiene 28 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE28
Últimos 12 meses5
Críticas1
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.
CVE-2023-33107Alta (7.8)0.74%⚠ Explotación activa5 dic 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-24088Alta (8.2)0.07%—1 jun 2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-47383Alta (7.2)0.14%—2 mar 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47320Alta (7.8)0.08%—18 dic 2025
Memory corruption while processing MFC channel configuration during music playback.
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-21483Crítica (9.8)0.40%—24 sept 2025
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-21487Alta (8.2)0.26%—24 sept 2025
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
CVE-2025-21484Alta (8.2)0.26%—24 sept 2025
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
CVE-2024-53026Alta (8.2)0.30%—3 jun 2025
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2024-53021Alta (8.2)0.24%—3 jun 2025
Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2024-53020Alta (8.2)0.24%—3 jun 2025
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2025-21429Alta (7.5)0.26%—7 abr 2025
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
CVE-2025-21428Alta (7.5)0.25%—7 abr 2025
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
CVE-2024-45552Alta (8.2)0.26%—7 abr 2025
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
CVE-2024-38423Alta (7.8)0.10%—4 nov 2024
Memory corruption while processing GPU page table switch.
CVE-2024-38422Alta (7.8)0.10%—4 nov 2024
Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-33043Media (5.5)0.09%—2 sept 2024
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
CVE-2024-23357Media (5.5)0.09%—5 ago 2024
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
CVE-2024-23353Alta (7.5)0.35%—5 ago 2024
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2024-21461Alta (7.8)0.10%—1 jul 2024
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
CVE-2023-43513Alta (7.8)0.11%—6 feb 2024
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
CVE-2023-33110Alta (7)0.08%—2 ene 2024
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close…
CVE-2023-33033Alta (7.8)0.12%—2 ene 2024
Memory corruption in Audio during playback with speaker protection.
CVE-2023-33030Alta (7.8)0.12%—2 ene 2024
Memory corruption in HLOS while running playready use-case.
CVE-2023-33107Alta (7.8)0.74%⚠ Explotación activa5 dic 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
CVE-2023-28588Alta (7.5)0.52%—5 dic 2023
Transient DOS in Bluetooth Host while rfc slot allocation.
CVE-2023-28546Alta (7.8)0.11%—5 dic 2023
Memory Corruption in SPS Application while exporting public key in sorter TA.
CVE-2023-24850Alta (7.8)0.12%—3 oct 2023
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application9
  2. T1059 Command and Scripting Interpreter7
  3. T1068 Exploitation for Privilege Escalation7
  4. T1005 Data from Local System5
  5. T1499.004 Application or System Exploitation2
  6. T1041 Exfiltration Over C2 Channel1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm