CVE-2025-21466
7.8Qualcomm · Snapdragon (AQT1000, FastConnect 6200, FastConnect 6700, FastConnect 6800, FastConnect 6900, FastConnect 7800, QCA6391, QCA6420)
A use-after-free memory corruption vulnerability exists in multiple Qualcomm Snapdragon and FastConnect components, triggered during the processing of a private escape command in an event trigger.
Executive summary
A critical use-after-free vulnerability in Qualcomm Snapdragon and FastConnect components poses a severe risk of local privilege escalation and system compromise.
Vulnerability
This vulnerability is a use-after-free (CWE-416) flaw that occurs when processing a private escape command within an event trigger. According to the CVSS vector (AV:L/PR:L), this attack requires local, low-privileged access to the system.
Business impact
The vulnerability carries a CVSS score of 7.8, reflecting its potential for high impact on confidentiality, integrity, and availability. Successful exploitation allows a local attacker with low privileges to potentially execute arbitrary code or cause system instability, which could lead to unauthorized data access or a complete denial of service for the affected hardware.
Remediation
Immediate Action: Consult the July 2025 Qualcomm Security Bulletin and apply the latest firmware or driver updates provided by the device manufacturer.
Proactive Monitoring: Monitor system logs for unusual crashes or unexpected behavior in processes associated with Qualcomm wireless or connectivity drivers.
Compensating Controls: Ensure that systems are configured to restrict local access to untrusted users and maintain strict hardware-level access controls where possible.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the high CVSS severity and the potential for total impact on the affected hardware, security teams should prioritize the deployment of vendor-supplied patches. Coordinate with hardware vendors to obtain the necessary updates, as these are critical for mitigating the risk of exploitation in environments utilizing the specified Qualcomm components.