« Back to list

Qualcomm

Qualcomm Snapdragon 820 Automotive Platform Firmware: vulnerabilities and CVEs

Qualcomm Snapdragon 820 Automotive Platform Firmware has 69 published vulnerabilities, 7 of them in the last 12 months. 3 are rated critical and 2 are listed by CISA as actively exploited.

CVEs69
Last 12 months7
Critical3
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-21385High (7.8)1.3%⚠ Active exploitationMar 2, 2026
Memory corruption while using alignments for memory allocation.
CVE-2023-33107High (7.8)0.74%⚠ Active exploitationDec 5, 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-24088High (8.2)0.07%—Jun 1, 2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
CVE-2026-21385High (7.8)1.3%⚠ Active exploitationMar 2, 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-47383High (7.2)0.14%—Mar 2, 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47320High (7.8)0.08%—Dec 18, 2025
Memory corruption while processing MFC channel configuration during music playback.
CVE-2025-47362Medium (6.1)0.08%—Nov 4, 2025
Information disclosure while processing message from client with invalid payload.
CVE-2025-27074High (7.8)0.09%—Nov 4, 2025
Memory corruption while processing a GP command response.
CVE-2025-27053High (7.8)0.09%—Oct 9, 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-47318High (7.5)0.21%—Sep 24, 2025
Transient DOS while parsing the EPTM test control message to get the test pattern.
CVE-2025-21483Critical (9.8)0.40%—Sep 24, 2025
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-21488High (8.2)0.27%—Sep 24, 2025
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
CVE-2025-21487High (8.2)0.26%—Sep 24, 2025
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
CVE-2025-21484High (8.2)0.26%—Sep 24, 2025
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
CVE-2025-27062High (7.8)0.08%—Aug 6, 2025
Memory corruption while handling client exceptions, allowing unauthorized channel access.
CVE-2024-53026High (8.2)0.30%—Jun 3, 2025
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2024-53020High (8.2)0.24%—Jun 3, 2025
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2024-53013Medium (6.6)0.09%—Jun 3, 2025
Memory corruption may occur while processing voice call registration with user.
CVE-2025-21430High (7.5)0.26%—Apr 7, 2025
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
CVE-2025-21429High (7.5)0.26%—Apr 7, 2025
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
CVE-2025-21428High (7.5)0.25%—Apr 7, 2025
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
CVE-2024-45552High (8.2)0.26%—Apr 7, 2025
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
CVE-2024-45543Medium (6.6)0.11%—Apr 7, 2025
Memory corruption while accessing MSM channel map and mixer functions.
CVE-2024-43066High (7.8)0.11%—Apr 7, 2025
Memory corruption while handling file descriptor during listener registration/de-registration.
CVE-2024-33056High (7.8)0.10%—Dec 2, 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-38423High (7.8)0.10%—Nov 4, 2024
Memory corruption while processing GPU page table switch.
CVE-2024-38422High (7.8)0.10%—Nov 4, 2024
Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-33043Medium (5.5)0.09%—Sep 2, 2024
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
CVE-2024-33014High (7.5)0.32%—Aug 5, 2024
Transient DOS while parsing ESP IE from beacon/probe response frame.
CVE-2024-23353High (7.5)0.35%—Aug 5, 2024
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2024-23373High (7.8)0.15%—Jul 1, 2024
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
CVE-2024-23368High (7.8)0.10%—Jul 1, 2024
Memory corruption when allocating and accessing an entry in an SMEM partition.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation11
  2. T1190 Exploit Public-Facing Application11
  3. T1059 Command and Scripting Interpreter9
  4. T1005 Data from Local System7
  5. T1499.004 Application or System Exploitation3
  6. T1041 Exfiltration Over C2 Channel1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm