CVE-2025-21466

7.8

Qualcomm · Snapdragon (AQT1000, FastConnect 6200, FastConnect 6700, FastConnect 6800, FastConnect 6900, FastConnect 7800, QCA6391, QCA6420)

A use-after-free memory corruption vulnerability exists in multiple Qualcomm Snapdragon and FastConnect components, triggered during the processing of a private escape command in an event trigger.

Executive summary

A critical use-after-free vulnerability in Qualcomm Snapdragon and FastConnect components poses a severe risk of local privilege escalation and system compromise.

Vulnerability

This vulnerability is a use-after-free (CWE-416) flaw that occurs when processing a private escape command within an event trigger. According to the CVSS vector (AV:L/PR:L), this attack requires local, low-privileged access to the system.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its potential for high impact on confidentiality, integrity, and availability. Successful exploitation allows a local attacker with low privileges to potentially execute arbitrary code or cause system instability, which could lead to unauthorized data access or a complete denial of service for the affected hardware.

Remediation

Immediate Action: Consult the July 2025 Qualcomm Security Bulletin and apply the latest firmware or driver updates provided by the device manufacturer.

Proactive Monitoring: Monitor system logs for unusual crashes or unexpected behavior in processes associated with Qualcomm wireless or connectivity drivers.

Compensating Controls: Ensure that systems are configured to restrict local access to untrusted users and maintain strict hardware-level access controls where possible.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Given the high CVSS severity and the potential for total impact on the affected hardware, security teams should prioritize the deployment of vendor-supplied patches. Coordinate with hardware vendors to obtain the necessary updates, as these are critical for mitigating the risk of exploitation in environments utilizing the specified Qualcomm components.

More Qualcomm CVEs

Sources