CVE-2025-21445

7.8

Qualcomm · Snapdragon

A buffer overflow vulnerability in Qualcomm Snapdragon processors allows for memory corruption during data transmission between a virtual machine and the host.

Executive summary

A critical memory corruption vulnerability in multiple Qualcomm Snapdragon products allows for potential system compromise through buffer overflow.

Vulnerability

The flaw is a classic buffer overflow (CWE-120) occurring when copying data to a shared transmission queue between a virtual machine and the host. An attacker requires local access and low privileges to trigger this memory corruption.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high severity risk. Successful exploitation could lead to unauthorized data access, privilege escalation, or total system compromise, potentially resulting in significant operational disruption and data loss within affected environments.

Remediation

Immediate Action: Review the official Qualcomm security bulletin for July 2025 to identify and apply the necessary firmware or driver updates for your specific device model.

Proactive Monitoring: Monitor system logs for unusual crash reports or unexpected behavior related to virtual machine processes and inter-processor communication.

Compensating Controls: Implement strict access controls for local users to limit the potential for unauthorized code execution and minimize the attack surface of the virtualization layer.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for total impact on the affected system, organizations should prioritize the identification of vulnerable hardware within their fleet. Apply all vendor-supplied security patches as soon as they become available to mitigate the risk of memory corruption and potential system-wide exploitation.

More Qualcomm CVEs

Sources