CVE-2025-27046

7.8

Qualcomm · Snapdragon

A double free vulnerability in Qualcomm Snapdragon components allows for local memory corruption through simultaneous escape calls.

Executive summary

A critical memory corruption vulnerability in various Qualcomm Snapdragon products poses a significant risk of local privilege escalation and system compromise.

Vulnerability

This vulnerability is categorized as a double free (CWE-415) occurring during the processing of multiple simultaneous escape calls. An attacker with local access and low privileges can leverage this flaw to trigger memory corruption, potentially leading to unauthorized code execution or system instability.

Business impact

The CVSS score of 7.8 indicates a high severity risk, primarily due to the potential for total loss of confidentiality, integrity, and availability. While the attack requires local access, the nature of the vulnerability could allow a malicious actor to elevate privileges, compromise sensitive device data, or gain persistent control over the affected hardware.

Remediation

Immediate Action: Review the July 2025 Qualcomm security bulletin and apply the vendor-supplied firmware or driver updates as soon as they become available for your specific device.

Proactive Monitoring: Monitor system logs for unusual crashes or service restarts that may indicate attempted exploitation of memory management functions.

Compensating Controls: Restrict local user access to the device and ensure that all installed applications are sourced from trusted vendors to minimize the opportunity for malicious local code execution.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of this memory corruption vulnerability, organizations should prioritize the deployment of firmware updates provided by Qualcomm and their respective hardware OEMs. While the local access requirement mitigates the risk of remote attacks, the potential for privilege escalation necessitates a prompt patching cycle to ensure device security.

More Qualcomm CVEs

Sources