Vulnerability record · CVE-2021-1905 · published 7 May 2021
CVE-2021-1905: Qualcomm Snapdragon chipsets use-after-free in memory mapping handling
Qualcomm · Apq8009 Firmware
A use-after-free flaw exists in multiple Qualcomm Snapdragon chipset families due to improper handling of memory mapping when multiple processes operate simultaneously. The vulnerability affects a broad set of firmware products across Auto, Compute, Connectivity, Consumer IOT, Industrial IOT, Mobile, Voice & Music, and Wearables platforms. Because it is a memory corruption issue, successful exploitation can lead to code execution or system compromise.
Description
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe vulnerability is in CISA's Known Exploited Vulnerabilities catalog and has a CVSS score of 7.8, but requires local access and low privileges, limiting widespread remote exploitation.
What it is
A use-after-free flaw exists in multiple Qualcomm Snapdragon chipset families due to improper handling of memory mapping when multiple processes operate simultaneously. The vulnerability affects a broad set of firmware products across Auto, Compute, Connectivity, Consumer IOT, Industrial IOT, Mobile, Voice & Music, and Wearables platforms. Because it is a memory corruption issue, successful exploitation can lead to code execution or system compromise.
Impact
An attacker who can run code on the affected device can corrupt memory and potentially execute arbitrary code with the privileges of the vulnerable component. This can lead to full compromise of confidentiality, integrity, and availability of the device.
Attack surface
The CVSS vector indicates a local attack (AV:L) requiring low privileges (PR:L) and no user interaction (UI:N). The flaw is reached through local memory mapping operations involving multiple processes, not over a network.
Exploitation
CVE-2021-1905 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. EPSS gives a 30-day exploitation probability of 0.01543 (73.7th percentile), and no ransomware campaign use is documented.
What to do
- Apply the Qualcomm May 2021 security bulletin updates for all affected chipsets as soon as possible.
- Follow vendor-specific firmware update instructions for each affected product line.
- Restrict local access and limit untrusted code execution on affected devices where patching is delayed.
- Monitor CISA KEV guidance and apply required actions by the due date.
- Inventory all devices using the listed Qualcomm chipsets to ensure complete patch coverage.
Detection
- Monitor for unexpected crashes or memory corruption events in processes handling memory mapping on affected devices.
- Audit local process activity for attempts to exploit use-after-free conditions, such as repeated mapping and unmapping of shared memory.
- Use endpoint detection to flag anomalous privilege escalation or code execution originating from local low-privileged processes.
- Track firmware versions against the Qualcomm May 2021 bulletin to identify unpatched devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-1905 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Qualcomm Multiple Chipsets Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.qualcomm.com/company/product-security/bulletins/may-2021-bulletin | PatchVendor Advisory |
| https://www.qualcomm.com/company/product-security/bulletins/may-2021-bulletin | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1905 | US Government Resource |
Track CVE-2021-1905 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-1905), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.