CVE-2025-21473

7.8

Qualcomm · Snapdragon

A memory corruption vulnerability exists in the Virtual Camera Data Mover component of various Qualcomm Snapdragon products, potentially allowing local attackers to achieve system compromise.

Executive summary

A memory corruption vulnerability in the Qualcomm Virtual Camera Data Mover component poses a significant security risk by allowing local attackers to potentially execute arbitrary code or cause system instability.

Vulnerability

This is a time of check time of use (TOCTOU) race condition (CWE-367) that leads to memory corruption when writing registers. An attacker must have low privileges on the local system to trigger the flaw.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high severity risk that could lead to full confidentiality, integrity, and availability loss if exploited. Because this involves memory corruption at the hardware or driver level, successful exploitation could grant an attacker elevated control over the device, leading to unauthorized data access or complete system compromise.

Remediation

Immediate Action: Review the August 2025 Qualcomm Security Bulletin and apply the latest firmware or driver updates provided by your device manufacturer.

Proactive Monitoring: Monitor system logs for unusual crashes or unauthorized attempts to access camera-related driver interfaces.

Compensating Controls: Ensure that only trusted applications are installed on devices and maintain strict control over user permissions to prevent unauthorized local execution.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the critical nature of the affected hardware components, organizations should prioritize the deployment of vendor-supplied patches as soon as they become available. Users and administrators should track the August 2025 Qualcomm Security Bulletin to ensure that all affected Snapdragon-based devices are updated to the secure version.

More Qualcomm CVEs

Sources