CVE-2021-1905
KEVmassUse-After-Free in Qualcomm Snapdragon Chipsets Allows Local Privilege Escalation
CISA: Qualcomm Multiple Chipsets Use-After-Free Vulnerability
CVE-2021-1905 is a use-after-free flaw (CWE-416) in firmware for a broad set of Qualcomm chipsets, caused by improper handling of memory mapping of multiple processes simultaneously. A local attacker who can already run low-privileged code on an affected device can trigger the stale-memory access, and with high confidentiality, integrity, and availability impact (CVSS 3.1 7.8, local vector, low privileges), successful exploitation can yield arbitrary code execution and privilege escalation. It affects devices built on Snapdragon platforms across the Auto, Compute, Connectivity, Consumer IOT, Industrial IOT, Mobile, Voice & Music, and Wearables lines, with CISA listing chipset firmware including APQ8009, APQ8017, APQ8053, APQ8096AU, AQT1000, AR8031/8035/8151, and CSRA6620/6640. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, and contemporaneous reporting described a Qualcomm zero-day under active targeted attacks that was quietly patched in that month's Android security updates, confirming exploitation in the wild. No public proof-of-concept is known, and EPSS estimates about a 1.5% probability of exploitation in the next 30 days (73rd percentile).
What to do: Apply the updated chipset firmware/drivers per Qualcomm's security advisory, and for phones and tablets install the latest Android monthly security update (November 2021 or later, per related reporting) and verify the device's security patch level. Because exploitation requires local code execution (AV:L), prioritize patching endpoints used by high-risk or targeted users and check with automotive, IoT, and networking equipment vendors for updated firmware. No workaround is documented, so treat KEV-listed, unpatched devices as at risk.
| Qualcomm APQ8009 firmware | — |
| Qualcomm APQ8009W firmware | — |
| Qualcomm APQ8017 firmware | — |
| Qualcomm APQ8053 firmware | — |
| Qualcomm APQ8064AU firmware | — |
| Qualcomm APQ8096AU firmware | — |
| Qualcomm AQT1000 firmware | — |
| Qualcomm AR8031 firmware | — |
| Qualcomm AR8035 firmware | — |
| Qualcomm AR8151 firmware | — |
| Qualcomm CSRA6620 firmware | — |
| Qualcomm CSRA6640 firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- Affected
- Qualcomm Multiple Chipsets
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- qualcomm
- Products
- apq8009 firmware, apq8009w firmware, apq8017 firmware, apq8053 firmware, apq8064au firmware, apq8096au firmware, aqt1000 firmware, ar8031 firmware, ar8035 firmware, ar8151 firmware, csra6620 firmware, csra6640 firmware
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H