CVE-2025-21487

8.2

Qualcomm · Snapdragon

A buffer over-read vulnerability in Qualcomm Snapdragon chipsets allows for information disclosure via malformed RTP packets.

Executive summary

An unauthenticated remote attacker can exploit a buffer over-read vulnerability in Qualcomm Snapdragon chipsets to disclose sensitive information from memory.

Vulnerability

This is a buffer over-read (CWE-126) occurring during the decoding of Real-time Transport Protocol (RTP) packets. The vulnerability is triggered when a network-received packet specifies a payload length exceeding the allocated buffer, allowing an unauthenticated attacker to read out-of-bounds memory.

Business impact

The vulnerability carries a CVSS score of 8.2, reflecting its high potential for unauthorized data access. Successful exploitation could lead to the exposure of sensitive cryptographic keys, user data, or system state information stored in memory, potentially facilitating further attacks against the device or the broader network environment.

Remediation

Immediate Action: Review the September 2025 Qualcomm Security Bulletin and apply the latest firmware or driver updates provided by the device manufacturer for the affected Snapdragon components.

Proactive Monitoring: Monitor network traffic for malformed or unusually large RTP packets targeting mobile or wireless infrastructure hardware.

Compensating Controls: While difficult to mitigate at the network edge, ensure that perimeter firewalls or intrusion detection systems are configured to inspect and drop anomalous traffic patterns associated with RTP streaming services.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Given the critical nature of chipset-level vulnerabilities, organizations should prioritize the deployment of vendor-supplied patches as soon as they become available. Failure to address this flaw leaves affected devices susceptible to remote information disclosure, which could be leveraged to compromise broader system integrity.

More Qualcomm CVEs

Sources