« Back to list

Qualcomm

Qualcomm Snapdragon 782g Mobile Platform Firmware: vulnerabilities and CVEs

Qualcomm Snapdragon 782g Mobile Platform Firmware has 77 published vulnerabilities, 19 of them in the last 12 months. 4 are rated critical and 3 are listed by CISA as actively exploited.

CVEs77
Last 12 months19
Critical4
Actively exploited3

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-21385High (7.8)1.3%⚠ Active exploitationMar 2, 2026
Memory corruption while using alignments for memory allocation.
CVE-2023-33106High (7.8)0.79%⚠ Active exploitationDec 5, 2023
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
CVE-2023-33107High (7.8)0.74%⚠ Active exploitationDec 5, 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-25275High (7.5)0.19%—Sep 17, 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-24084High (7.5)0.25%—Aug 4, 2026
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
CVE-2026-24079High (8.1)0.21%—Aug 4, 2026
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVE-2026-24078Medium (6.5)0.17%—Aug 4, 2026
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2026-24077Medium (6.5)0.17%—Aug 4, 2026
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
CVE-2026-24091High (7.2)0.10%—Jun 1, 2026
Memory corruption while processing fastboot commands with improperly formatted input.
CVE-2026-24085High (7.2)0.10%—Jun 1, 2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
CVE-2025-59610Medium (6.4)0.06%—Jun 1, 2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
CVE-2025-59605High (7.8)0.07%—Jun 1, 2026
Memory Corruption when processing device identifier strings that exceed the expected maximum length.
CVE-2025-59604High (7.8)0.07%—Jun 1, 2026
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVE-2025-47392High (8.8)0.17%—Apr 6, 2026
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
CVE-2025-47389High (7.8)0.10%—Apr 6, 2026
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
CVE-2026-21385High (7.8)1.3%⚠ Active exploitationMar 2, 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-47386High (7.8)0.07%—Mar 2, 2026
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
CVE-2025-47384Medium (6.5)0.11%—Mar 2, 2026
Transient DOS when MAC configures config id greater than supported maximum value.
CVE-2025-47383High (7.2)0.14%—Mar 2, 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47379High (7.8)0.07%—Mar 2, 2026
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
CVE-2025-47376High (7.8)0.07%—Mar 2, 2026
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
CVE-2025-47375High (7.8)0.07%—Mar 2, 2026
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
CVE-2024-33056High (7.8)0.10%—Dec 2, 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-33044High (7.8)0.10%—Dec 2, 2024
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
CVE-2024-38422High (7.8)0.10%—Nov 4, 2024
Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-38415High (7.8)0.10%—Nov 4, 2024
Memory corruption while handling session errors from firmware.
CVE-2024-38408Critical (9.1)0.14%—Nov 4, 2024
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
CVE-2024-33043Medium (5.5)0.09%—Sep 2, 2024
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
CVE-2024-33023High (7.8)0.11%—Aug 5, 2024
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
CVE-2024-33014High (7.5)0.32%—Aug 5, 2024
Transient DOS while parsing ESP IE from beacon/probe response frame.
CVE-2024-23357Medium (5.5)0.09%—Aug 5, 2024
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
CVE-2023-43536High (7.5)0.32%—Feb 6, 2024
Transient DOS while parse fils IE with length equal to 1.
CVE-2023-43533High (7.5)0.32%—Feb 6, 2024
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter15
  2. T1068 Exploitation for Privilege Escalation14
  3. T1190 Exploit Public-Facing Application3
  4. T1210 Exploitation of Remote Services3
  5. T1040 Network Sniffing2
  6. T1091 Replication Through Removable Media2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm