CVE-2025-21476: Buffer Copy Without Checking Size of Input in Computer Vision

Published Sep 24, 2025
·
Updated

Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.

Affected Software

84 affected components
All of the following
Qualcomm Qcs6490 Firmware
Qualcomm Qcs6490
All of the following
Qualcomm Qcs8550 Firmware
Qualcomm Qcs8550
All of the following
Qualcomm Qcs9100 Firmware
Qualcomm Qcs9100
All of the following
Qualcomm Sg8275 Firmware
Qualcomm Sg8275
All of the following
Qualcomm Sg8275p Firmware
Qualcomm Sg8275p
All of the following
Qualcomm Sm6650 Firmware
Qualcomm Sm6650
All of the following
Qualcomm Sm7635 Firmware
Qualcomm Sm7635
All of the following
Qualcomm Sm7675 Firmware
Qualcomm Sm7675
All of the following
Qualcomm Sm7675p Firmware
Qualcomm Sm7675p
All of the following
Qualcomm Sm8550 Firmware
Qualcomm Sm8550
All of the following
Qualcomm Sm8550p Firmware
Qualcomm Sm8550p
All of the following
Qualcomm Sm8635 Firmware
Qualcomm Sm8635
All of the following
Qualcomm Sm8635p Firmware
Qualcomm Sm8635p
All of the following
Qualcomm Sm8650 Firmware
Qualcomm Sm8650
All of the following
Qualcomm Sm8650p Firmware
Qualcomm Sm8650p
All of the following
Qualcomm Sm8650q Firmware
Qualcomm Sm8650q
All of the following
Qualcomm Sm8750 Firmware
Qualcomm Sm8750
All of the following
Qualcomm Sm8750p Firmware
Qualcomm Sm8750p
All of the following
Qualcomm Sxr2330p Firmware
Qualcomm Sxr2330p
All of the following
Qualcomm Qca6391 Firmware
Qualcomm Qca6391
All of the following
Qualcomm Qca6698aq Firmware
Qualcomm Qca6698aq
All of the following
Qualcomm Qcn9011 Firmware
Qualcomm Qcn9011
All of the following
Qualcomm Qcn9012 Firmware
Qualcomm Qcn9012
All of the following
Qualcomm Qcn9274 Firmware
Qualcomm Qcn9274
All of the following
Qualcomm Wcn3910 Firmware
Qualcomm Wcn3910
All of the following
Qualcomm Wcn3950 Firmware
Qualcomm Wcn3950
All of the following
Qualcomm Wcn6650 Firmware
Qualcomm Wcn6650
All of the following
Qualcomm Wcn6750 Firmware
Qualcomm Wcn6750
All of the following
Qualcomm Wcn6755 Firmware
Qualcomm Wcn6755
All of the following
Qualcomm Wcn6855 Firmware
Qualcomm WCN6855
All of the following
Qualcomm Wcn6856 Firmware
Qualcomm Wcn6856
All of the following
Qualcomm Wcn7850 Firmware
Qualcomm Wcn7850
All of the following
Qualcomm Wcn7851 Firmware
Qualcomm Wcn7851
All of the following
Qualcomm Wcn7860 Firmware
Qualcomm Wcn7860
All of the following
Qualcomm Wcn7861 Firmware
Qualcomm Wcn7861
All of the following
Qualcomm Wcn7880 Firmware
Qualcomm Wcn7880
All of the following
Qualcomm Wcn7881 Firmware
Qualcomm Wcn7881
All of the following
Qualcomm Qcm5430 Firmware
Qualcomm Qcm5430
All of the following
Qualcomm Qcm6490 Firmware
Qualcomm Qcm6490
All of the following
Qualcomm Qcm8550 Firmware
Qualcomm Qcm8550
All of the following
Qualcomm Qcs5430 Firmware
Qualcomm Qcs5430
All of the following
Qualcomm Qcs615 Firmware
Qualcomm Qcs615

Event History

Sep 24, 2025
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-21476?

CVE-2025-21476 is classified as a high severity vulnerability due to the potential for memory corruption during communications.

2

What types of devices are affected by CVE-2025-21476?

CVE-2025-21476 affects various Qualcomm firmware versions, including Qcs6490 and Qcs8550, among others.

3

How do I fix CVE-2025-21476?

To fix CVE-2025-21476, it is recommended to update to the latest firmware version provided by Qualcomm that addresses this vulnerability.

4

What impact does CVE-2025-21476 have on affected devices?

CVE-2025-21476 can lead to system instability and potential unauthorized access due to memory corruption.

5

Is there proof of exploit for CVE-2025-21476?

Currently, there is no public evidence to suggest that CVE-2025-21476 is being actively exploited in the wild.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203