CVE-2025-21461

7.8

Qualcomm · Snapdragon

A memory corruption vulnerability exists in Qualcomm Snapdragon processors due to out-of-bounds writes when programming registers through the virtual CDM.

Executive summary

A high-severity memory corruption vulnerability in Qualcomm Snapdragon processors may allow a local attacker with low privileges to achieve complete system compromise.

Vulnerability

This vulnerability is categorized as an out-of-bounds write (CWE-787) triggered when programming registers via virtual CDM. It requires an attacker to have local, low-privileged access to the affected hardware to execute the exploit.

Business impact

The potential for memory corruption leading to total system impact presents a significant risk to data confidentiality, integrity, and availability. With a CVSS score of 7.8, this vulnerability is classified as High severity, as it could allow unauthorized code execution or system crashes, resulting in potential service disruption or unauthorized access to sensitive device data.

Remediation

Immediate Action: Organizations should review the August 2025 Qualcomm Security Bulletin and apply the latest vendor-supplied firmware or driver updates as soon as they become available for the specific hardware models.

Proactive Monitoring: Security teams should monitor device logs for signs of unexpected system restarts or kernel-level errors that may indicate exploitation attempts.

Compensating Controls: Ensure that device access is strictly managed and that only authorized users or processes have the necessary permissions to interact with hardware-level registers.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high impact of this memory corruption flaw, it is imperative that IT and security teams prioritize the identification of affected Snapdragon hardware within their environments. Administrators must coordinate with device vendors to obtain and deploy the necessary security patches, as firmware updates are the only effective method to remediate the underlying register programming error.

More Qualcomm CVEs

Sources