← Vulnerability feed

Vulnerability record · CVE-2021-1905 · published 7 May 2021

CVE-2021-1905: Qualcomm Snapdragon chipsets use-after-free in memory mapping handling

Qualcomm · Apq8009 Firmware

A use-after-free flaw exists in multiple Qualcomm Snapdragon chipset families due to improper handling of memory mapping when multiple processes operate simultaneously. The vulnerability affects a broad set of firmware products across Auto, Compute, Connectivity, Consumer IOT, Industrial IOT, Mobile, Voice & Music, and Wearables platforms. Because it is a memory corruption issue, successful exploitation can lead to code execution or system compromise.

7.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 1.5% · top 26.1% CWE-416 · Use after free
7.8CVSS 3.1 base score, v2 7.2
1.5%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
150Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe vulnerability is in CISA's Known Exploited Vulnerabilities catalog and has a CVSS score of 7.8, but requires local access and low privileges, limiting widespread remote exploitation.

What it is

A use-after-free flaw exists in multiple Qualcomm Snapdragon chipset families due to improper handling of memory mapping when multiple processes operate simultaneously. The vulnerability affects a broad set of firmware products across Auto, Compute, Connectivity, Consumer IOT, Industrial IOT, Mobile, Voice & Music, and Wearables platforms. Because it is a memory corruption issue, successful exploitation can lead to code execution or system compromise.

Impact

An attacker who can run code on the affected device can corrupt memory and potentially execute arbitrary code with the privileges of the vulnerable component. This can lead to full compromise of confidentiality, integrity, and availability of the device.

Attack surface

The CVSS vector indicates a local attack (AV:L) requiring low privileges (PR:L) and no user interaction (UI:N). The flaw is reached through local memory mapping operations involving multiple processes, not over a network.

Exploitation

CVE-2021-1905 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. EPSS gives a 30-day exploitation probability of 0.01543 (73.7th percentile), and no ransomware campaign use is documented.

What to do

  • Apply the Qualcomm May 2021 security bulletin updates for all affected chipsets as soon as possible.
  • Follow vendor-specific firmware update instructions for each affected product line.
  • Restrict local access and limit untrusted code execution on affected devices where patching is delayed.
  • Monitor CISA KEV guidance and apply required actions by the due date.
  • Inventory all devices using the listed Qualcomm chipsets to ensure complete patch coverage.

Detection

  • Monitor for unexpected crashes or memory corruption events in processes handling memory mapping on affected devices.
  • Audit local process activity for attempts to exploit use-after-free conditions, such as repeated mapping and unmapping of shared memory.
  • Use endpoint detection to flag anomalous privilege escalation or code execution originating from local low-privileged processes.
  • Track firmware versions against the Qualcomm May 2021 bulletin to identify unpatched devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-1905 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Qualcomm Multiple Chipsets Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-1905 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-33107Qualcomm Graphics Linux integer overflow memory corruptionCVE-2023-33107 is an integer overflow (CWE-190) in Qualcomm Graphics Linux that causes memory corruption when a shared virtual memory region is assig…KEVEPSS 0.89%analysed7.8CVE-2023-33063Qualcomm DSP Services use-after-free memory corruptionCVE-2023-33063 is a use-after-free memory corruption flaw in Qualcomm DSP Services, triggered during a remote call from the high-level operating syst…KEVEPSS 0.69%analysed7.8CVE-2022-22071Qualcomm chipset shell memory use-after-free via IOCTL munmapA use-after-free exists in Qualcomm Snapdragon and related chipset firmware when process shell memory is freed through an IOCTL munmap call while pro…KEVEPSS 0.46%analysed7.8CVE-2020-11261Qualcomm Snapdragon chipsets memory corruption via improper allocation size checkQualcomm Snapdragon firmware fails to return an error when a user application requests a very large memory allocation, leading to memory corruption (…KEVEPSS 1.6%analysed5.5CVE-2021-1906Qualcomm Snapdragon GPU address deregistration failure causes allocation denialImproper handling of address deregistration on failure in Qualcomm Snapdragon chipsets can cause subsequent GPU address allocation to fail. The flaw …KEVEPSS 0.52%analysed9.8CVE-2025-21483Qualcomm apq8017 firmware memory buffer overflow vulnerabilityMemory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.EPSS 0.40%9.8CVE-2023-22388Qualcomm 315 5g iot modem firmware out-of-bounds write vulnerabilityMemory Corruption in Multi-mode Call Processor while processing bit mask API.EPSS 0.35%9.8CVE-2023-22385Qualcomm 315 5g iot modem firmware out-of-bounds write vulnerabilityMemory Corruption in Data Modem while making a MO call or MT VOLTE call.EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2021-1905), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.