« Back to list

Qualcomm

Qualcomm Vision Intelligence 400 Platform Firmware: vulnerabilities and CVEs

Qualcomm Vision Intelligence 400 Platform Firmware has 116 published vulnerabilities, 9 of them in the last 12 months. 2 are rated critical and 3 are listed by CISA as actively exploited.

CVEs116
Last 12 months9
Critical2
Actively exploited3

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-21385High (7.8)1.3%⚠ Active exploitationMar 2, 2026
Memory corruption while using alignments for memory allocation.
CVE-2023-33063High (7.8)0.69%⚠ Active exploitationDec 5, 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33107High (7.8)0.89%⚠ Active exploitationDec 5, 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-25275High (7.5)0.19%—Sep 17, 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-24091High (7.2)0.10%—Jun 1, 2026
Memory corruption while processing fastboot commands with improperly formatted input.
CVE-2026-24085High (7.2)0.10%—Jun 1, 2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
CVE-2025-59610Medium (6.4)0.06%—Jun 1, 2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
CVE-2026-21385High (7.8)1.3%⚠ Active exploitationMar 2, 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-47383High (7.2)0.14%—Mar 2, 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47333Medium (6.6)0.08%—Jan 7, 2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
CVE-2025-47320High (7.8)0.08%—Dec 18, 2025
Memory corruption while processing MFC channel configuration during music playback.
CVE-2025-27053High (7.8)0.09%—Oct 9, 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-27032High (7.8)0.08%—Sep 24, 2025
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
CVE-2025-21484High (8.2)0.26%—Sep 24, 2025
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
CVE-2025-21482High (7.1)0.08%—Sep 24, 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-27066High (7.5)0.28%—Aug 6, 2025
Transient DOS while processing an ANQP message.
CVE-2025-21465Medium (6.5)0.09%—Aug 6, 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Medium (6.5)0.09%—Aug 6, 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2025-21463High (7.5)0.23%—Jun 3, 2025
Transient DOS while processing the EHT operation IE in the received beacon frame.
CVE-2024-53026High (8.2)0.30%—Jun 3, 2025
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2024-53021High (8.2)0.24%—Jun 3, 2025
Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2024-53020High (8.2)0.24%—Jun 3, 2025
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
CVE-2024-53010High (7.8)0.08%—Jun 3, 2025
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
CVE-2025-21434High (7.5)0.26%—Apr 7, 2025
Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
CVE-2024-49848Medium (6.7)0.14%—Apr 7, 2025
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.
CVE-2024-45552High (8.2)0.26%—Apr 7, 2025
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
CVE-2024-43066High (7.8)0.11%—Apr 7, 2025
Memory corruption while handling file descriptor during listener registration/de-registration.
CVE-2024-43046Medium (5.5)0.11%—Apr 7, 2025
There may be information disclosure during memory re-allocation in TZ Secure OS.
CVE-2024-33058High (7.5)0.09%—Apr 7, 2025
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
CVE-2024-43048High (7.8)0.10%—Dec 2, 2024
Memory corruption when invalid input is passed to invoke GPU Headroom API call.
CVE-2024-33063High (7.5)0.26%—Dec 2, 2024
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.
CVE-2024-33056High (7.8)0.10%—Dec 2, 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-33044High (7.8)0.10%—Dec 2, 2024
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter18
  2. T1068 Exploitation for Privilege Escalation18
  3. T1190 Exploit Public-Facing Application10
  4. T1005 Data from Local System4
  5. T1499.004 Application or System Exploitation3
  6. T1091 Replication Through Removable Media2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm