CVE-2025-21432

7.8

Qualcomm · Snapdragon

A memory corruption vulnerability exists in multiple Qualcomm Snapdragon products due to improper handling of CBOR data, potentially leading to unauthorized system impact.

Executive summary

A memory corruption vulnerability in Qualcomm Snapdragon products poses a high risk of local system compromise and requires immediate vendor-supplied security updates.

Vulnerability

The vulnerability is a double free (CWE-415) occurring during the retrieval of CBOR data from a Trusted Application (TA). An attacker with low privileges on the local system can trigger this memory corruption to achieve high confidentiality, integrity, and availability impact.

Business impact

The CVSS score of 7.8 indicates a high severity rating, reflecting the potential for total system compromise if the vulnerability is successfully exploited. While the attack requires local access, the ability to corrupt memory within a Trusted Application environment could lead to the bypass of critical security boundaries, resulting in unauthorized data access and potential service instability.

Remediation

Immediate Action: Review the July 2025 Qualcomm Security Bulletin and apply the latest firmware updates provided by your device manufacturer as soon as they become available.

Proactive Monitoring: Monitor system logs for unusual crashes or service restarts that may indicate triggered memory corruption events within Trusted Applications.

Compensating Controls: Ensure that device access is strictly controlled, as this vulnerability requires local access to the affected hardware components for exploitation.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score and the nature of the vulnerability within the trusted execution environment, this issue should be treated as a significant security priority. Administrators should track the official Qualcomm security bulletin and coordinate with hardware vendors to ensure patch deployment is prioritized as soon as updates are published for specific devices.

More Qualcomm CVEs

Sources