ThreatCluster

Multiple CVEs Addressed in Firmware Security Updates

First seen 18 Feb 2026, 11:17 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Two security vulnerabilities in firmware have been reported, affecting ARM and Qualcomm devices. CVE-2025-37905, published on May 20, 2025, addresses device reference counting issues, while CVE-2024-57852, published on February 27, 2025, deals with missing SCM device handling. Both vulnerabilities have been acknowledged in recent publications.

Timeline

2025-02-27
CVE-2024-57852 published
2025-05-20
CVE-2025-37905 published
2026-02-18
Information published on CVE-2025-37905
2026-02-18
Information published on CVE-2024-57852