CVE-2025-27037

7.8

Qualcomm · Snapdragon

A use-after-free vulnerability in the camera kernel driver allows for memory corruption during the processing of config_dev IOCTL requests.

Executive summary

A critical use-after-free vulnerability in Qualcomm Snapdragon components allows for local memory corruption, potentially leading to unauthorized code execution.

Vulnerability

This vulnerability is a use-after-free (CWE-416) flaw occurring within the camera kernel driver when it drops references to CPU buffers during config_dev IOCTL processing. An attacker with local access and low privileges can trigger this condition to achieve memory corruption.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high severity level. Successful exploitation allows a local attacker to manipulate system memory, which may lead to full system compromise, data theft, or persistent denial of service. Given the core nature of kernel-level drivers, the impact on device integrity and user privacy is significant.

Remediation

Immediate Action: Consult the official Qualcomm Security Bulletin for September 2025 and apply the relevant firmware or driver updates provided by your device manufacturer.

Proactive Monitoring: Monitor system logs for kernel-level crashes or unexpected reboots, which may indicate attempts to trigger memory corruption flaws.

Compensating Controls: Ensure that device access is strictly controlled, as this vulnerability requires local access for exploitation. Utilize endpoint security solutions capable of detecting abnormal kernel behavior.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a high risk due to the potential for privilege escalation and system-wide impact. Organizations and individual users should prioritize applying the security updates referenced in the Qualcomm bulletin as soon as they are made available by their specific hardware vendors to eliminate the risk of exploitation.

More Qualcomm CVEs

Sources