CVE-2025-27044

7.8

Qualcomm · Snapdragon

A memory corruption vulnerability exists in Qualcomm Snapdragon components during timestamp video decoding, potentially leading to unauthorized system impact.

Executive summary

A memory corruption vulnerability in various Qualcomm Snapdragon products poses a high risk of local system compromise if exploited by a low-privileged attacker.

Vulnerability

This is an out-of-bounds write vulnerability (CWE-787) triggered during the processing of video decode commands with large input values. The vulnerability requires a locally authenticated attacker with low privileges to execute code or manipulate memory, as indicated by the CVSS vector PR:L.

Business impact

The exploitation of this memory corruption flaw can lead to a total loss of confidentiality, integrity, and availability for the affected system. With a CVSS score of 7.8, this high-severity vulnerability represents a significant risk to device stability and data security, potentially allowing an attacker to escalate privileges or crash critical system services.

Remediation

Immediate Action: Review the July 2025 Qualcomm Security Bulletin and apply the latest firmware updates provided by your device manufacturer or OEM.

Proactive Monitoring: Monitor system logs for unexpected crashes or service restarts associated with video decoding or media processing modules.

Compensating Controls: Ensure that device security policies restrict access to low-privileged user accounts and maintain strict control over applications capable of interacting with hardware-level decoding drivers.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Given the potential for total system compromise, organizations should prioritize the deployment of vendor-supplied firmware updates as soon as they become available. Administrators should verify their device hardware against the affected list and coordinate with hardware vendors to ensure the latest patches are applied to mitigate this high-risk memory corruption vulnerability.

More Qualcomm CVEs

Sources