Skip to content
COOEY

FAIL › dossier

Qualcomm

VENDOR

· dossier confidence 20%

PROFILE
Categorysemiconductor and telecommunications equipmentWhat they doQualcomm Inc. is an American multinational company known for its Snapdragon processors. Websitehttps://www.qualcomm.com ↗
SECURITY POSTURE

The company has faced multiple security vulnerabilities, with several high-severity issues identified and addressed.

Notable failures
  • CVE-2026-21385 (high [RCE])
  • CVE-2025-27038 (high [RCE])
  • CVE-2025-21479 (high [RCE])
  • CVE-2025-21480 (high [RCE])
  • CVE-2024-43047 (high)
  • CVE-2023-33063 (high)
  • CVE-2023-33107 (high)
  • CVE-2023-33106 (high)
  • CVE-2023-22071 (high)
  • CVE-2021-1906 (high)
  • CVE-2021-1905 (high)
  • CVE-2020-11261 (high)
  • CVE-2021-1103 (high)
Patterns: Repeated unpatched edge-device RCEs; Use-After-Free vulnerabilities; Memory corruption issues
FAILURE HISTORY · 12
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2021-1905 high Qualcomm chipsets suffered a use-after-free vulnerability that was actively exploited in the wild, enabling remote code execution and privilege escalation.
2021-12-01 CVE-2020-11261 high Qualcomm Snapdragon chipsets suffered from a memory corruption vulnerability due to improper input validation on large memory allocation requests.
2026-03-03 CVE-2026-21385 high Memory corruption in Qualcomm chipsets exploited in the wild
2025-06-03 CVE-2025-21480 high Qualcomm chipsets exploited for unauthorized command execution
2025-06-03 CVE-2025-21479 high Qualcomm chipsets exploited for unauthorized command execution
2025-06-03 CVE-2025-27038 high Use-After-Free in Qualcomm chipsets exploited in wild
2021-11-03 CVE-2021-1906 high Qualcomm chipsets had an unpatched error-handling flaw that caused GPU allocation failures and was actively exploited in the wild.
2024-10-08 CVE-2024-43047 high Qualcomm chipsets contain a use-after-free vulnerability in DSP Services that is actively exploited in the wild.
2023-12-05 CVE-2023-33107 high Qualcomm chipsets contain an integer overflow vulnerability in Graphics Linux that allows memory corruption during IOCTL calls.
2023-12-05 CVE-2023-33106 high Qualcomm chipsets contain a high-severity out-of-range pointer offset vulnerability in graphics memory handling that is actively exploited in the wild.
2023-12-05 CVE-2023-33063 high Qualcomm chipsets contain a remote use-after-free vulnerability actively exploited in the wild.
2023-12-05 CVE-2022-22071 high Qualcomm chipsets contained a use-after-free vulnerability actively exploited in the wild, impacting DIB organizations relying on these components.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Qualcomm's use-after-free flaw in multiple chipsets was a significant security oversight, though the provided source lacks explicit sentiment or vendor response details, resulting in a neutral-to-nega
synthesissevere-fallout-0.60
Qualcomm's GPU driver flaws were noted as giving hackers full control, indicating severe fallout despite limited targeted exploitation reports.
cooey ↗severe-fallout-0.50
Neutral technical disclosure without condemnation.
"Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure."
rottenwifi.com ↗severe-fallout-0.70
Negative - flaws gave hackers full control.
"4 vulnerabilities under attack gave hackers full control of some Android devices (2021). The 4 vulnerabilities under attack were CVE-2021-1905, CVE-2021-1906, CVE-2021-28663, and CVE-2021-28664, GPU-driver flaws affecting some Qualcomm Adreno and Arm Mali Android devices in 2021."
sec.cloudapps.cisco.com ↗severe-fallout+0.00
Irrelevant - Cisco advisory unrelated to Qualcomm.
The Hacker News ↗severe-fallout-0.80
Severe - Unisoc exploit chain shows similar severe fallout for chipset vendors.
"Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker."
sam.gov ↗severe-fallout+0.00
Irrelevant - SAM.gov procurement data.
www.cvefind.com ↗severe-fallout+0.00
Irrelevant - CVE database listing.
cooey ↗severe-fallout+0.00
Neutral factual disclosure; no sentiment or vendor response expressed in the provided text.
www.comparitech.com ↗severe-fallout+0.00
Irrelevant - Ransomware map.
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-27 03:40:57.738207+00:00