« Back to list

Qualcomm

Qualcomm Snapdragon 850 Mobile Compute Platform Firmware: vulnerabilities and CVEs

Qualcomm Snapdragon 850 Mobile Compute Platform Firmware has 54 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs54
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-27032High (7.8)0.08%—Sep 24, 2025
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
CVE-2025-27066High (7.5)0.28%—Aug 6, 2025
Transient DOS while processing an ANQP message.
CVE-2025-21465Medium (6.5)0.09%—Aug 6, 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Medium (6.5)0.09%—Aug 6, 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2024-53010High (7.8)0.08%—Jun 3, 2025
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
CVE-2024-43046Medium (5.5)0.11%—Apr 7, 2025
There may be information disclosure during memory re-allocation in TZ Secure OS.
CVE-2024-33058High (7.5)0.09%—Apr 7, 2025
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
CVE-2024-33056High (7.8)0.10%—Dec 2, 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-33044High (7.8)0.10%—Dec 2, 2024
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
CVE-2024-33016Medium (6.8)0.15%—Sep 2, 2024
memory corruption when an invalid firehose patch command is invoked.
CVE-2024-23362High (7.1)0.12%—Sep 2, 2024
Cryptographic issue while parsing RSA keys in COBR format.
CVE-2024-21481High (8.4)0.11%—Aug 5, 2024
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
CVE-2024-21469High (7.8)0.10%—Jul 1, 2024
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
CVE-2024-21465High (7.8)0.10%—Jul 1, 2024
Memory corruption while processing key blob passed by the user.
CVE-2024-21462Medium (5.5)0.09%—Jul 1, 2024
Transient DOS while loading the TA ELF file.
CVE-2023-43536High (7.5)0.32%—Feb 6, 2024
Transient DOS while parse fils IE with length equal to 1.
CVE-2023-43533High (7.5)0.32%—Feb 6, 2024
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
CVE-2023-33076High (7.8)0.11%—Feb 6, 2024
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
CVE-2023-33072High (7.8)0.11%—Feb 6, 2024
Memory corruption in Core while processing control functions.
CVE-2023-43511High (7.5)0.32%—Jan 2, 2024
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
CVE-2023-33110High (7)0.08%—Jan 2, 2024
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close…
CVE-2023-33109High (7.5)0.34%—Jan 2, 2024
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
CVE-2023-33062High (7.5)0.34%—Jan 2, 2024
Transient DOS in WLAN Firmware while parsing a BTM request.
CVE-2023-33036Medium (5.5)0.10%—Jan 2, 2024
Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.
CVE-2023-33033High (7.8)0.12%—Jan 2, 2024
Memory corruption in Audio during playback with speaker protection.
CVE-2023-33030High (7.8)0.12%—Jan 2, 2024
Memory corruption in HLOS while running playready use-case.
CVE-2023-33080High (7.5)0.34%—Dec 5, 2023
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-28586Medium (6.5)0.14%—Dec 5, 2023
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
CVE-2023-28585High (8.8)0.14%—Dec 5, 2023
Memory corruption while loading an ELF segment in TEE Kernel.
CVE-2023-28550High (7.8)0.12%—Dec 5, 2023
Memory corruption in MPP performance while accessing DSM watermark using external memory address.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation5
  2. T1059 Command and Scripting Interpreter4
  3. T1190 Exploit Public-Facing Application1
  4. T1499 Endpoint Denial of Service1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm