Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Snapdragon — Vulnerabilities & Security Advisories 962

All 962 CVE vulnerabilities found in Snapdragon, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations (CWE) associated with Qualcomm’s Snapdragon product line and its related components. It serves as a centralized reference for security researchers and engineers to understand the historical and current security posture of these mobile and embedded processing platforms. The content compiles a comprehensive collection of vulnerabilities affecting Snapdragon SoCs, including issues in the Adreno graphics drivers, Hexagon DSPs, Modem processors, and the TrustZone-based security ecosystem. The data covers the time range from the early release of the Snapdragon series up to the most recent firmware and driver updates. By organizing these entries by weakness type and specific subsystem, the page provides a structured view of how different coding errors, configuration missteps, and architectural limitations have manifested over time within this widely deployed hardware family. Here, readers can track Qualcomm’s advisory patterns to see how quickly and effectively the vendor responds to discovered flaws. Users can gain a deeper understanding of specific weakness classes, such as buffer overflows or race conditions, as they apply to mobile chipset architectures. Additionally, this resource allows for the lookup of a product’s vulnerability history, enabling stakeholders to assess the long-term security maintenance and patch lifecycle of individual Snapdragon generations. This information supports informed decision-making for device manufacturers, system integrators, and security auditors who need to evaluate the risk profile of Snapdragon-based devices in various deployment scenarios.

Vendor: Qualcomm, Inc.

CVE IDTitleCVSSSeverityPublished
CVE-2025-21429 Buffer Over-read in WLAN Host CWE-126 7.5 High2025-04-07
CVE-2025-21428 Buffer Over-read in WLAN Host CWE-126 7.5 High2025-04-07
CVE-2025-21425 Improper Access Control in Automotive Linux OS CWE-284 7.3 High2025-04-07
CVE-2025-21423 Improper Validation of Array Index in Display CWE-129 7.8 High2025-04-07
CVE-2025-21421 Buffer Over-read in Display CWE-126 7.8 High2025-04-07
CVE-2024-49848 Use After Free in DSP Service CWE-416 6.7 Medium2025-04-07
CVE-2024-45557 Use of Out-of-range Pointer Offset in Trust Management Engine CWE-823 7.8 High2025-04-07
CVE-2024-45556 Improper Access Control for Register Interface in TZ Firmware CWE-1262 6.5 Medium2025-04-07
CVE-2024-45552 Buffer Over-read in Data Network Stack & Connectivity CWE-126 8.2 High2025-04-07
CVE-2024-45551 Weak Authentication in HLOS CWE-1390 6.2 Medium2025-04-07
CVE-2024-45549 Exposure of Sensitive System Information to an Unauthorized Control Sphere in KERNEL CWE-497 7.7 High2025-04-07
CVE-2024-45544 Use After Free in Data Network Stack & Connectivity CWE-416 6.6 Medium2025-04-07
CVE-2024-45543 Out-of-bounds Write in Audio CWE-787 6.6 Medium2025-04-07
CVE-2024-45540 Use After Free in HLOS CWE-416 6.6 Medium2025-04-07
CVE-2024-43067 Time-of-check Time-of-use (TOCTOU) Race Condition in Camera CWE-367 7.8 High2025-04-07
CVE-2024-43066 Use After Free in HLOS CWE-416 7.8 High2025-04-07
CVE-2024-43065 Exposed Dangerous Method or Function in HLOS CWE-749 7.1 High2025-04-07
CVE-2024-43058 Incorrect Type Conversion or Cast in Multimedia Frameworks CWE-704 7.8 High2025-04-07
CVE-2024-43046 Information Exposure in TZ Secure OS CWE-200 5.5 Medium2025-04-07
CVE-2024-33058 Insufficient Granularity of Access Control in Core CWE-1220 7.5 High2025-04-07
CVE-2025-21424 Use After Free in NPU CWE-416 7.8 High2025-03-03
CVE-2024-53034 Untrusted Pointer Dereference in DSP_Services CWE-822 7.8 High2025-03-03
CVE-2024-53033 Untrusted Pointer Dereference in DSP_Services CWE-822 7.8 High2025-03-03
CVE-2024-53032 Time-of-check Time-of-use (TOCTOU) Race Condition in Automotive OS Platform CWE-367 7.8 High2025-03-03
CVE-2024-53031 Improper Input Validation in Automotive OS Platform CWE-20 7.8 High2025-03-03
CVE-2024-53030 Improper Input Validation in Automotive OS Platform CWE-20 7.8 High2025-03-03
CVE-2024-53029 Improper Input Validation in Automotive OS Platform CWE-20 7.8 High2025-03-03
CVE-2024-53028 Time-of-check Time-of-use (TOCTOU) Race Condition in Automotive Vehicle Networks CWE-367 7.8 High2025-03-03
CVE-2024-53027 Buffer Copy Without Checking Size of Input in WLAN Host CWE-120 7.5 High2025-03-03
CVE-2024-53025 Integer Overflow or Wraparound in BT Controller CWE-190 5.5 Medium2025-03-03

All 962 known CVE vulnerabilities affecting Snapdragon with full Chinese analysis, references, and POCs where available.