<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Qualcomm</title><description>Actively exploited vulnerabilities affecting Qualcomm products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/qualcomm.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-21385 — Qualcomm Multiple Chipsets Memory Corruption Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-21385</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-21385</guid><description>Multiple Qualcomm chipsets contain a memory corruption flaw triggered during memory allocation alignment operations. Memory corruption vulnerabilities are serious because attackers can exploit them to crash systems, escalate privileges, or execute arbitrary code. Since Qualcomm chips power a wide range of devices — including smartphones, IoT hardware, and networking equipment — this vulnerability has a broad potential attack surface affecting many device categories and their users.</description><pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate><category>Qualcomm</category><category>Multiple Chipsets</category></item><item><title>CVE-2025-21479 — Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-21479</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-21479</guid><description>Multiple Qualcomm chipsets contain an incorrect authorization flaw in GPU micronodes that allows unauthorized command execution when a specific sequence of commands is processed, leading to memory corruption. Because Qualcomm chips power a vast range of Android devices and embedded systems, this vulnerability could be exploited to corrupt memory at a low hardware level, potentially enabling privilege escalation or code execution on affected devices. The broad chipset scope makes widespread exposure likely.</description><pubDate>Tue, 03 Jun 2025 00:00:00 GMT</pubDate><category>Qualcomm</category><category>Multiple Chipsets</category></item><item><title>CVE-2025-21480 — Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-21480</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-21480</guid><description>Multiple Qualcomm chipsets contain a flaw where commands sent to the GPU micronode can bypass authorization checks, leading to memory corruption. An attacker who can execute a specific sequence of GPU commands could exploit this to corrupt memory, potentially gaining elevated privileges or causing system instability. Because Qualcomm chips are widely deployed across mobile devices, embedded systems, and networking hardware, the attack surface for this vulnerability is broad.</description><pubDate>Tue, 03 Jun 2025 00:00:00 GMT</pubDate><category>Qualcomm</category><category>Multiple Chipsets</category></item><item><title>CVE-2025-27038 — Qualcomm Multiple Chipsets Use-After-Free Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-27038</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-27038</guid><description>A use-after-free flaw in Qualcomm&apos;s Adreno GPU drivers can corrupt memory during graphics rendering in Chrome, potentially allowing an attacker to execute arbitrary code or crash affected systems. Because this involves widely deployed Qualcomm chipsets — common in Android devices and embedded systems — the attack surface is broad. Memory corruption vulnerabilities of this class are frequently exploitable and can lead to full device compromise if triggered through malicious web content.</description><pubDate>Tue, 03 Jun 2025 00:00:00 GMT</pubDate><category>Qualcomm</category><category>Multiple Chipsets</category></item></channel></rss>