CVE-2025-21474

7.8

Qualcomm · Snapdragon FastConnect and QAM/QCA chipsets

A use-after-free vulnerability in the A2dp sink command queue of various Qualcomm Snapdragon components allows for local memory corruption.

Executive summary

A critical use-after-free vulnerability in Qualcomm Snapdragon components may allow a local attacker to achieve elevated privileges or system compromise.

Vulnerability

This vulnerability is a use-after-free (CWE-416) condition occurring during the processing of commands within the A2dp sink command queue. An attacker with local access and low privileges can trigger this flaw to achieve total technical impact, including potential code execution or system instability.

Business impact

The CVSS score of 7.8 signifies a high-severity risk, particularly for mobile and embedded devices utilizing affected Qualcomm hardware. Successful exploitation could lead to unauthorized access to sensitive user data, complete system compromise, or persistent denial of service, posing significant risks to organizational data integrity and device availability.

Remediation

Immediate Action: Consult the official Qualcomm August 2025 security bulletin to identify specific firmware or driver updates provided by the device manufacturer for your hardware.

Proactive Monitoring: Monitor system logs for unusual crashes or service restarts associated with wireless or Bluetooth communication modules.

Compensating Controls: Ensure device hardening policies are enforced, such as restricting physical access and minimizing the installation of untrusted applications that could facilitate local exploitation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for high-impact compromise, administrators and device owners should prioritize tracking the release of vendor-specific firmware updates. Because this vulnerability affects low-level hardware components, applying the manufacturer-provided patch is the only effective way to fully remediate the underlying memory corruption risk.

More Qualcomm CVEs

Sources