Evidence dossier

CVE-2025-27038

Use After Free in Graphics

Exploited in the wild (CISA KEV since Jun 3, 2025). qualcomm reports CVSS 3.1 7.5. EPSS estimates 0.8% exploit likelihood as of Aug 27, 2026.

70.070.7Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

State
PUBLISHED
Published
Jun 3, 2025
Updated
Feb 26, 2026
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    qualcomm

    Record text: Use After Free in Graphics

    Inspect raw assertion
    Field
    container
    Value
    Use After Free in Graphics
    Original evidence ↗
  3. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Qualcomm Multiple Chipsets Use-After-Free Vulnerability
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 0.84% probability · 55.08th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.008350000000; percentile 0.550840000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Jun 3, 2025 · first observed Jul 19, 2026

Exploit likelihood0.83%

FIRST EPSS · score date Aug 27, 2026 · 55.1th percentile · first observed Aug 27, 2026

SeverityCVSS 7.5

qualcomm · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
qualcommOriginal assertion
Record text

Use After Free in Graphics

Inspect raw assertion
Field
container
Value
Use After Free in Graphics
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

0.84% probability · 55.08th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.008350000000; percentile 0.550840000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
88Underlying assertions
88Canonical products
44Target assertions
44Constraint assertions

Grouped from 88 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

89 scope groups

qualcomm · source assertedQualcomm, Inc.SnapdragonDirect source scope
Affected: AR8031Affected: CSRA6620Affected: CSRA6640Affected: FastConnect 7800Affected: QCA2066Affected: QCA6391Affected: QCM6125Affected: QCM8550Affected: QCN9011Affected: QCN9012Affected: QCS6125Affected: QCS8550Affected: Qualcommr Video Collaboration VC1 PlatformAffected: SM6475Affected: SM6650Affected: SM6650PAffected: SM7435Affected: SM7635Affected: SM7635PAffected: Smart Audio 400 PlatformAffected: Snapdragon 4 Gen 2 Mobile PlatformAffected: Snapdragon 6 Gen 1 Mobile PlatformAffected: Snapdragon 680 4G Mobile PlatformAffected: Snapdragon 685 4G Mobile Platform (SM6225-AD)Affected: Snapdragon W5+ Gen 1 Wearable PlatformAffected: SW5100Affected: SW5100PAffected: WCD9335Affected: WCD9370Affected: WCD9375Affected: WCD9378Affected: WCD9385Affected: WCD9395Affected: WCN3950Affected: WCN3980Affected: WCN3988Affected: WCN6650Affected: WCN6740Affected: WCN6755Affected: WSA8810Affected: WSA8815Affected: WSA8830Affected: WSA8832Affected: WSA8835
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "AR8031"}, {"status": "affected", "version": "CSRA6620"}, {"status": "affected", "version": "CSRA6640"}, {"status": "affected", "version": "FastConnect 7800"}, {"status": "affected", "version": "QCA2066"}, {"status": "affected", "version": "QCA6391"}, {"status": "affected", "version": "QCM6125"}, {"status": "affected", "version": "QCM8550"}, {"status": "affected", "version": "QCN9011"}, {"status": "affected", "version": "QCN9012"}, {"status": "affected", "version": "QCS6125"}, {"status": "affected", "version": "QCS8550"}, {"status": "affected", "version": "Qualcommr Video Collaboration VC1 Platform"}, {"status": "affected", "version": "SM6475"}, {"status": "affected", "version": "SM6650"}, {"status": "affected", "version": "SM6650P"}, {"status": "affected", "version": "SM7435"}, {"status": "affected", "version": "SM7635"}, {"status": "affected", "version": "SM7635P"}, {"status": "affected", "version": "Smart Audio 400 Platform"}, {"status": "affected", "version": "Snapdragon 4 Gen 2 Mobile Platform"}, {"status": "affected", "version": "Snapdragon 6 Gen 1 Mobile Platform"}, {"status": "affected", "version": "Snapdragon 680 4G Mobile Platform"}, {"status": "affected", "version": "Snapdragon 685 4G Mobile Platform (SM6225-AD)"}, {"status": "affected", "version": "Snapdragon W5+ Gen 1 Wearable Platform"}, {"status": "affected", "version": "SW5100"}, {"status": "affected", "version": "SW5100P"}, {"status": "affected", "version": "WCD9335"}, {"status": "affected", "version": "WCD9370"}, {"status": "affected", "version": "WCD9375"}, {"status": "affected", "version": "WCD9378"}, {"status": "affected", "version": "WCD9385"}, {"status": "affected", "version": "WCD9395"}, {"status": "affected", "version": "WCN3950"}, {"status": "affected", "version": "WCN3980"}, {"status": "affected", "version": "WCN3988"}, {"status": "affected", "version": "WCN6650"}, {"status": "affected", "version": "WCN6740"}, {"status": "affected", "version": "WCN6755"}, {"status": "affected", "version": "WSA8810"}, {"status": "affected", "version": "WSA8815"}, {"status": "affected", "version": "WSA8830"}, {"status": "affected", "version": "WSA8832"}, {"status": "affected", "version": "WSA8835"}]
NVD CPE · HARDWAREqualcommar8031Environmental constraint · 1 assertions
Version not applicableCanonical identity product-57d9088f59b0247c7d5668465d091577719f022a5ad484bf92119136e3baf900Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:qualcomm:ar8031:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bb1de046-dd70-4aca-9df4-59939dac1889
NVD CPE · OPERATING SYSTEMqualcommar8031_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-b9295b19c919e4d8738db792da74af9a0579eb8d9d8c8c263e16c785efe5b027Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:qualcomm:ar8031_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fce1ada9-8042-4cde-a2b9-e96665cb41be
NVD CPE · HARDWAREqualcommcsra6620Environmental constraint · 1 assertions
Version not applicableCanonical identity product-cc9d618bd48ab00dbf7eb0355693ff1405abe93c902db7c9e2cea6e40ef533adLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:qualcomm:csra6620:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bfcf207d-b8c8-4860-89c7-673c821f0237
NVD CPE · OPERATING SYSTEMqualcommcsra6620_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-71a9996015b5843aa4538cb1b732d2a3b1fffd7ba1efd05b0248a6fe9913720bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:qualcomm:csra6620_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fa42f2ea-5d00-42b8-b020-c27675b72915
NVD CPE · HARDWAREqualcommcsra6640Environmental constraint · 1 assertions
Version not applicableCanonical identity product-5a0842b1e0927e963da9a379b4742d9ff5533b637a815b25fb73e6edd2f366daLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:qualcomm:csra6640:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    65b283d6-b2d2-49b6-98a8-08edb54c1f15
NVD CPE · OPERATING SYSTEMqualcommcsra6640_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-07685b9cfc5716c0f4025369d4ef9f7b5e0d2e3bbb842828b42cd6ac79d032a3Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:qualcomm:csra6640_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a8a35ecf-b12e-42de-a74b-2c3be03639a4
NVD CPE · HARDWAREqualcommfastconnect_7800Environmental constraint · 1 assertions
Version not applicableCanonical identity product-3cf88252274c089006fa15b26075841e188c97e20b3167cd2c694151193997cbLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    638dbc7f-456f-487d-bed2-2214dff8bee2
NVD CPE · OPERATING SYSTEMqualcommfastconnect_7800_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-68be08ace024336eb5ba1c15857e2db34de88b73dadd8e0eb34013bc23844e04Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b3053d68-c5d8-4d47-a4f0-9f3af2289e1d
NVD CPE · HARDWAREqualcommqca2066Environmental constraint · 1 assertions
Version not applicableCanonical identity product-1111d60eba6c52077d222331570cd29ada5bb1f13a85d95f0be589776d3f67faLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:qualcomm:qca2066:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    09b688af-e1a4-496c-924c-d6b725cbbe26
NVD CPE · OPERATING SYSTEMqualcommqca2066_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-d1fa7b4e973930f0d1722216d17d725f3c91086070ec6b93cbdec98cdf1d9e22Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:qualcomm:qca2066_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6366f2ed-c6b7-4579-b304-c5b6df951eb4
NVD CPE · HARDWAREqualcommqca6391Environmental constraint · 1 assertions
Version not applicableCanonical identity product-6ee34877adaaa3db3d1b9dd528d0f091907e99968a4112b950ecdd3ece2872adLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:qualcomm:qca6391:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6febc0c5-caa1-475c-96c2-b8d24b2e4536
NVD CPE · OPERATING SYSTEMqualcommqca6391_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-009a51d383c0d6cf3eb55ef2647aae0edb58085cbc0c3eeea4abcd7b88dfcaf1Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:qualcomm:qca6391_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    83b53119-1b2f-4978-b7f5-33b84be73b68
NVD CPE · HARDWAREqualcommqcm6125Environmental constraint · 1 assertions
Version not applicableCanonical identity product-f6366bdf4f3150f258c4731a88ad4421d4852878f5da409d2633247ad3cda6f7Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:qualcomm:qcm6125:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fbb16dc4-cdc9-4936-9c6a-0ed8e1f6d056
NVD CPE · OPERATING SYSTEMqualcommqcm6125_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-e2de1532ce3e95e31d6af0d6c4087436b5a79a7c7f4e9008935e61a42cbfb073Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:qualcomm:qcm6125_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ab226552-52d9-44f5-a170-35c44761a72b
NVD CPE · HARDWAREqualcommqcm8550Environmental constraint · 1 assertions
Version not applicableCanonical identity product-0a31605fd8cddc643c360acb102a477b1a61b4aedd1e4f0aeb847ff581c81703Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:qualcomm:qcm8550:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5654ffb5-9a89-4399-afab-0a26726dec81
NVD CPE · OPERATING SYSTEMqualcommqcm8550_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-556ba4b9da601bcb0b2cae0a0234f7396ba24eacd2d122da7c28d6ce2b7cf85bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:qualcomm:qcm8550_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    646b241b-2971-4929-9fb6-7a4cbf801cbb
NVD CPE · HARDWAREqualcommqcn9011Environmental constraint · 1 assertions
Version not applicableCanonical identity product-669bacc0ae557861f66b772862b1182149107ce5576955ac5e99fd704c702003Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:qualcomm:qcn9011:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    02ba009f-24e1-4953-ba95-2a5bc1cdbdbb
NVD CPE · OPERATING SYSTEMqualcommqcn9011_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-66d785adb3fec2a91592adf2e6222e6d61a154dd52367a49f65acc9a7608c1aeLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:qualcomm:qcn9011_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9306c34d-47e4-40cf-89f4-ba5263655d13
NVD CPE · HARDWAREqualcommqcn9012Environmental constraint · 1 assertions
Version not applicableCanonical identity product-09e501d0903efa9eaa298d705e4b94e3aba3a87f0e5ac4b4887d6d2d0b428346Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:qualcomm:qcn9012:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    9 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1a06879f-6fe9-448a-8186-8347d76f872b
NVD CPE · OPERATING SYSTEMqualcommqcn9012_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-33b51317a963889db2221ad3f36b850d7c2a0d24e9ebdffe6d0b1fcbca2786c7Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:qualcomm:qcn9012_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    61f34dd2-9dc0-49e5-bc85-1543ea199477
NVD CPE · HARDWAREqualcommqcs6125Environmental constraint · 1 assertions
Version not applicableCanonical identity product-a1a699c51c87de0e05935b0b10f6affe99c0cddb44509ee7583dc8d6fbe3da6aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:qualcomm:qcs6125:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6da2c3e1-e285-4cad-9fa3-813c8ec436f6
NVD CPE · OPERATING SYSTEMqualcommqcs6125_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-edc6ed48f86b966536a223c82f3d4f16bdca38bca3af84632edefb19afbd489cLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:qualcomm:qcs6125_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4468ea5d-87b0-4fec-a3db-617651b0d169
NVD CPE · HARDWAREqualcommqcs8550Environmental constraint · 1 assertions
Version not applicableCanonical identity product-fe028be67b23807a02d8ad4f98c844cbe91b138bf17ffe154ebf2b09ce1ef9c4Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:qualcomm:qcs8550:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    11 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5acb8afb-5b91-4aa1-ba3a-1af0b3503080
NVD CPE · OPERATING SYSTEMqualcommqcs8550_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-9ee9e6ec34f27a9fe9c5d68718a2964743a116c1e6eba4e1ee784a3ef3e30b7eLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:qualcomm:qcs8550_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fff23ddb-98a0-4343-add3-5ab9c2383e7e

Affected-product evidence

Accepted scope and product mapping

44 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-009a51d383c0d6cf3eb55ef2647aae0edb58085cbc0c3eeea4abcd7b88dfcaf1

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1380d1da-3f31-4d3f-89f8-1e7ee54815c7
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-07685b9cfc5716c0f4025369d4ef9f7b5e0d2e3bbb842828b42cd6ac79d032a3

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
522411d3-5c7f-4f11-b926-017ee7a14c4e
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-07c15887a850bc50c6a054a3cef8bd629d6a815cb1d064c208b809348e770dcf

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d9b734a0-0d72-459e-a3a4-c8ea6af6cabd
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-0df6acd618aa296a16bc576bbc88a268f5f121d1b9e1e538e27f4cdd4a18e9b8

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9de3a043-fd66-4171-9ac4-c5f5028648ef
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-187565ed9de9b60fd50e5251246e499234282320913b3d5e26d0be97063ac33c

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
602e4168-dc84-4e05-881a-7fe7dcf0e99d
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-25498134ed809854f264aac66776d810f7979800ed94e68545b534cbe34e5f39

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
880abcd8-fd27-4eb4-aaa5-307b11653792
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-2570b78bdd4b4e8f9be5d208cd3c203ed012596580c3e1de9e18d6aaef6db5a3

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
61be2707-a04a-44aa-b4e6-082fd12a8e84
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-33b51317a963889db2221ad3f36b850d7c2a0d24e9ebdffe6d0b1fcbca2786c7

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0d91149f-3516-4ce5-b790-248057f4ace5
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-350b44501e729489fb5036ea8716f897d327f4d25437c71a9d495a6d7f52b970

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
bc85ae10-254a-4a16-a6bf-73be5219fb3f
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-4b31c989eaf2286889ae00e7d2a751e1acd44e5ffba77fb41188bc840375a751

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2fefa773-c599-4a32-a61e-fa1b984189e1
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-52ea8a5d92b65e58f5626e12b2e91e50db12d266f4172840ef88badebebefb4f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7d7fc11d-174e-428b-92c7-2f833579065a
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-556ba4b9da601bcb0b2cae0a0234f7396ba24eacd2d122da7c28d6ce2b7cf85b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
346191c2-f81b-4509-b5c4-086783091f42
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-5fa7f1f258cc17eb6f781daeecb9a5b2061e1da2795c3c43acebb9998c9aa8fc

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6c9c87a9-d94f-4e13-958c-66bebf01152a
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-66d785adb3fec2a91592adf2e6222e6d61a154dd52367a49f65acc9a7608c1ae

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5e12db53-1294-44b3-a525-e1df5490c02d
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-68be08ace024336eb5ba1c15857e2db34de88b73dadd8e0eb34013bc23844e04

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6063775a-b54d-439b-9d51-b5feeb02cadb
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-68fe99e2b846d295d47d470ee72db34f17f5cae861217b69757f3a798402a9df

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
88318757-2041-4267-8648-691d5225b1a7
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-6dffee5c3784cf55c8d8a024b5fc6fa548add60218039f27cfc515e17fea39ce

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0f010289-9878-4069-8915-74badd328526
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-71a9996015b5843aa4538cb1b732d2a3b1fffd7ba1efd05b0248a6fe9913720b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
13798345-2ff8-4b36-95d3-fd951ee1f667
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-799043a5f4c20d8f49bbdac5b7c16881caf3be538202c889597bba631d4f96ff

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
67bf69ed-9ea2-490c-b5d9-7e0fa81ea1e2
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-7a4cbb9c7cedcf59b0ef757239feb35005f53f4307f91cd855126d7d82fbcd83

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b0b1d1d0-e4d0-4b9e-bfda-c45c9f7ee258
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-8544d6adfd871811db4d25fb20b24eb4b9cc9dbfef5d57c69cec868f187cf7f7

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
bd453b86-5de0-4090-9ac0-1b355f7d8117
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-8fdd915014d6b842975b2845540a0a40f451b6eb2cac8daf04e327835121172b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f9a43ff9-6184-417e-aa86-21a5c6da0ff7
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-8fedcc59fc0ac236e6e8c06fb223d7dbd445db201fbd4efcc7a3c4083feb9f8f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
134efcb4-e54a-4b88-aae6-21792902aed8
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-964c7044c849a6257117029c9f809206968e7ea8976e7fc99652a08a92863c30

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b189794b-e499-43ba-9ff0-168ab4ec63ea
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-99672a80fe1fb642076bd002b80924796b9028e2039756d96c48b88e5f4340f2

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
89511f00-b8fb-461f-953f-0a1c4cefe687
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-9ee9e6ec34f27a9fe9c5d68718a2964743a116c1e6eba4e1ee784a3ef3e30b7e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
19955853-1ca6-4096-9a3b-3430db9bb24f
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-a04b88de521f9f9689aaea83a0d1e5f94bad4457142faf6bab9d98637cf9ae9b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
22e9db35-5c77-42ed-b3a5-93874796b585
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-a66a7e7015ca339f3b7a9feb7a73b45702a1169e48ce4d8c3d5c2f4e1bd8b7bf

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
01781a4f-2701-4fa1-9ca1-f9ce403f93cb
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-a80ccf5fe4d748ecb6446ff57acd3913b2d64c12381b1479c71029c815d64a71

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
90580576-8048-42ac-b1a2-aa890e45894f
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-b857dddb2eaae8e12e73b92e2df4b32fecc3d0ea5f3e7b928c5c48687bb04050

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
117aad1a-b098-4129-8823-c6d0fba0735d
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-b9295b19c919e4d8738db792da74af9a0579eb8d9d8c8c263e16c785efe5b027

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
20490ee7-5dda-43aa-ae79-0556a38155a4
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-b96acb21e2e25e2f508d27f74923589c77ad72426b28a85e4872aba1f98c837c

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
34f0a19b-0126-446e-aa23-d4cb9442a3c3
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-c557852e4b16806490803fd1d77d8f5774538eeb0f9945260973880ee52a03fd

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6ab4364a-8be8-4b41-bb7a-efffc09c1c86
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-cdf246f4bf7bcf703e5c37c9fdc182135c05e1343fc49c4ec9e7c025abc60aeb

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
09e3aa17-ab48-4cd9-bf82-ccc8aa03444c
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-d1fa7b4e973930f0d1722216d17d725f3c91086070ec6b93cbdec98cdf1d9e22

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
64475cec-f835-4a84-a51c-090e517a73c6
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-d28e287a489c697c14d67db986f5098fc258510906c4a9ff5ba86322a27e3bbf

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
69d56cee-d268-4556-b950-5ccc7455b9de
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-d3a6a75ea4585863b3003a26acbf4004e7e26f4199d1dc7a52a8592baff0bbbc

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1f03b9b9-2a0e-4dd0-95cf-3feb2d4c4444
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-d6a865974521f7126ba0e93c4e44d39c6595b5e3ba4563f8c3c3de09bfcbd7d4

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7dd94ac4-2158-4cc1-9444-3e6b9415a703
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-d7438efe8ee1f18edcef939dfdba5b3795a5b476718ced6288903ad8de3f51cc

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
832b811e-6aae-4ca4-8213-d24c8de65213
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-d984b7b52b9f3f635b87e061eae87fa9d2dcb44558bf6653ed88ebe83e657d68

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
af44196e-3aed-4a94-8eb7-66fd17c1f656
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-e2de1532ce3e95e31d6af0d6c4087436b5a79a7c7f4e9008935e61a42cbfb073

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
69271c6b-9d28-4e49-a551-bf90158740af
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-edc6ed48f86b966536a223c82f3d4f16bdca38bca3af84632edefb19afbd489c

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
64ea29ac-035c-4fe1-9722-9e9e29381412
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-f2e1a81a2c14f598bec268d1e3d75e83b74b8133795b8c456ec1c8ab0c4f8202

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2cb2dab3-eb09-4c00-bd70-a8c3eb9ee80f
Mapping establishedEvidence supported

vendor-50b0f30c682cae2910688066c741ab17f6b7818151f595a6c6d4fa5fbfeda6ef · product-fa0833bbb2407280a5a1da88ec4b4991cca4f55d98d3bc7e0807d7fb110efd4b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e6666a00-04b9-4a68-b483-d8324663ad4d
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
884a6719-4cb9-47b0-8235-035cd10ed2d4

Assessments

CVSS by origin

7.5
product-security@qualcomm.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
7.5
qualcommCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

7.5Priority eligible

qualcomm

CVSS 3.1 · Primary · Original assertion · rank 1

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
7.5
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.