CVE-2025-21484

8.2

Qualcomm · Snapdragon

A buffer over-read vulnerability exists in Qualcomm Snapdragon processors during RTP packet reassembly, potentially allowing unauthorized information disclosure.

Executive summary

A critical information disclosure vulnerability in Qualcomm Snapdragon hardware allows unauthenticated remote attackers to potentially read sensitive memory data during RTP packet processing.

Vulnerability

This vulnerability, classified as a buffer over-read (CWE-126), occurs when the User Equipment (UE) decodes and reassembles fragmented RTP packets. The vulnerability is network-accessible and requires no authentication from the attacker.

Business impact

The exposure of sensitive memory contents can lead to the compromise of cryptographic keys, user data, or system metadata, resulting in a significant loss of confidentiality. Given the CVSS score of 8.2, this vulnerability is classified as High severity. The ability for an unauthenticated remote attacker to trigger this over-read across various Qualcomm chipsets presents a substantial risk to mobile and embedded device security.

Remediation

Immediate Action: Review the official September 2025 Qualcomm Security Bulletin and apply the latest firmware updates provided by the respective device manufacturer as soon as they become available.

Proactive Monitoring: Monitor network traffic for malformed or unusually fragmented RTP packets directed at mobile devices, which may indicate exploitation attempts.

Compensating Controls: Ensure that devices are protected by standard network security controls and that unnecessary network services are disabled to reduce the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations utilizing devices equipped with the affected Qualcomm Snapdragon chipsets should prioritize the deployment of vendor-supplied firmware updates. Given the potential for remote information disclosure, maintaining device hygiene and monitoring for anomalous network activity is essential until patches are successfully applied to all affected assets.

More Qualcomm CVEs

Sources