CVE-2025-21427

8.2

Qualcomm · Snapdragon

A buffer over-read vulnerability exists in Qualcomm Snapdragon processors during the decoding of RTP packet payloads, potentially leading to unauthorized information disclosure.

Executive summary

A high-severity buffer over-read vulnerability in various Qualcomm Snapdragon products allows unauthenticated remote attackers to potentially disclose sensitive information.

Vulnerability

This is a buffer over-read (CWE-126) vulnerability occurring during the decoding of RTP packet payloads. The vulnerability is network-accessible and does not require authentication or user interaction to trigger.

Business impact

The vulnerability carries a CVSS score of 8.2, reflecting a significant risk to data confidentiality. An attacker could potentially gain access to sensitive information residing in memory, leading to data breaches or the extraction of cryptographic material. Given the ubiquity of these components in mobile and networking devices, the potential for widespread impact is high.

Remediation

Immediate Action: Review the July 2025 Qualcomm Security Bulletin and apply the latest firmware or software updates provided by your device manufacturer.

Proactive Monitoring: Monitor network traffic for malformed RTP packets or anomalous traffic patterns directed at devices utilizing the affected Qualcomm chipsets.

Compensating Controls: Ensure that network-level security policies restrict access to vulnerable devices from untrusted sources to reduce the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the remote, unauthenticated nature of this vulnerability and its high CVSS score, organizations must prioritize the identification of affected hardware within their environment. Monitor vendor portals closely for specific patch releases and coordinate deployment as soon as updates become available from original equipment manufacturers.

More Qualcomm CVEs

Sources