Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Snapdragon — Vulnerabilities & Security Advisories 951

All 951 CVE vulnerabilities found in Snapdragon, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations (CWE) associated with Qualcomm’s Snapdragon product line and its related components. It serves as a centralized reference for security researchers and engineers to understand the historical and current security posture of these mobile and embedded processing platforms. The content compiles a comprehensive collection of vulnerabilities affecting Snapdragon SoCs, including issues in the Adreno graphics drivers, Hexagon DSPs, Modem processors, and the TrustZone-based security ecosystem. The data covers the time range from the early release of the Snapdragon series up to the most recent firmware and driver updates. By organizing these entries by weakness type and specific subsystem, the page provides a structured view of how different coding errors, configuration missteps, and architectural limitations have manifested over time within this widely deployed hardware family. Here, readers can track Qualcomm’s advisory patterns to see how quickly and effectively the vendor responds to discovered flaws. Users can gain a deeper understanding of specific weakness classes, such as buffer overflows or race conditions, as they apply to mobile chipset architectures. Additionally, this resource allows for the lookup of a product’s vulnerability history, enabling stakeholders to assess the long-term security maintenance and patch lifecycle of individual Snapdragon generations. This information supports informed decision-making for device manufacturers, system integrators, and security auditors who need to evaluate the risk profile of Snapdragon-based devices in various deployment scenarios.

Vendor: Qualcomm, Inc.

CVE IDTitleCVSSSeverityPublished
CVE-2026-25271 Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service CWE-367 7.8 High2026-07-06
CVE-2026-25268 Stack-based Buffer Overflow in WLAN Host CWE-121 8.8 High2026-07-06
CVE-2026-21384 Out-of-bounds Write in Camera Driver CWE-787 5.3 Medium2026-07-06
CVE-2026-21383 Reusing a Nonce, Key Pair in Encryption in HLOS CWE-323 7.1 High2026-07-06
CVE-2026-21379 Buffer Over-read in Windows Compute CWE-126 7.8 High2026-07-06
CVE-2026-21370 Out-of-bounds Write in Camera Driver CWE-787 5.3 Medium2026-07-06
CVE-2026-21369 Out-of-bounds Write in Camera Driver CWE-787 5.3 Medium2026-07-06
CVE-2026-21368 Out-of-bounds Write in Camera Driver CWE-787 5.3 Medium2026-07-06
CVE-2025-59617 Use After Free in Computer Vision CWE-416 6.6 Medium2026-07-06
CVE-2025-59616 Use After Free in Computer Vision CWE-416 6.6 Medium2026-07-06
CVE-2025-59615 Use After Free in Computer Vision CWE-416 6.6 Medium2026-07-06
CVE-2026-25277 Buffer Copy Without Checking Size of Input in Secure Processor CWE-120 8.8 High2026-06-01
CVE-2026-25276 Improper Validation of Array Index in Secure Processor CWE-129 8.8 High2026-06-01
CVE-2026-25260 Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service CWE-367 7.8 High2026-06-01
CVE-2026-25259 Out-of-bounds Write in DSP Service CWE-787 7.8 High2026-06-01
CVE-2026-25258 Out-of-bounds Read in DSP Service CWE-125 7.8 High2026-06-01
CVE-2026-24092 Improper Validation of Syntactic Correctness of Input in Display CWE-1286 7.2 High2026-06-01
CVE-2026-24091 Improper Validation of Syntactic Correctness of Input in Display CWE-1286 7.2 High2026-06-01
CVE-2026-24090 Missing Authentication for Critical Function in HLOS CWE-306 7.1 High2026-06-01
CVE-2026-24089 Improper Validation of Syntactic Correctness of Input in Kernel CWE-1286 7.2 High2026-06-01
CVE-2026-24088 Missing Authentication for Critical Function in Boot CWE-306 8.2 High2026-06-01
CVE-2026-24087 Improper Validation of Syntactic Correctness of Input in Kernel CWE-1286 7.2 High2026-06-01
CVE-2026-24085 Stack-based Buffer Overflow in Display CWE-121 7.2 High2026-06-01
CVE-2025-59614 Out-of-bounds Write in Windows Compute CWE-787 6.7 Medium2026-06-01
CVE-2025-59613 Stack-based Buffer Overflow in Windows Compute CWE-121 6.7 Medium2026-06-01
CVE-2025-59612 Stack-based Buffer Overflow in Windows Compute CWE-121 6.7 Medium2026-06-01
CVE-2025-59611 Out-of-bounds Write in Core Services CWE-787 6.7 Medium2026-06-01
CVE-2025-59610 Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Driver CWE-367 6.4 Medium2026-06-01
CVE-2025-59609 Buffer Over-read in WLAN Host Communication CWE-126 5.5 Medium2026-06-01
CVE-2025-59606 NULL Pointer Dereference in HLOS CWE-476 7.8 High2026-06-01

All 951 known CVE vulnerabilities affecting Snapdragon with full Chinese analysis, references, and POCs where available.