CVE-2025-27050

7.8

Qualcomm · Snapdragon (AQT1000, FastConnect series, QCA6391, QCA6420)

A use after free memory corruption vulnerability exists in various Qualcomm Snapdragon components, triggered during event close operations when a client process terminates unexpectedly.

Executive summary

A memory corruption vulnerability in multiple Qualcomm Snapdragon hardware components poses a high risk of local privilege escalation or system instability.

Vulnerability

This is a use after free vulnerability (CWE-416) that occurs during the processing of event close operations. The attack requires local access and low privileges to trigger the memory corruption state when a client process terminates abruptly.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high severity level that could lead to unauthorized system control or denial of service. Successful exploitation allows a local attacker to potentially execute arbitrary code with elevated privileges, leading to complete system compromise and loss of data confidentiality or integrity.

Remediation

Immediate Action: Review the July 2025 Qualcomm Security Bulletin and apply the recommended firmware or driver updates provided by your device manufacturer.

Proactive Monitoring: Monitor system logs for unexpected process crashes or kernel panic events that may indicate exploitation attempts.

Compensating Controls: Ensure that device security policies restrict local access to untrusted users and maintain strict application sandboxing to limit the impact of potential local exploits.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the high severity of this memory corruption flaw, organizations should prioritize firmware updates for all affected Qualcomm hardware. Coordinate with original equipment manufacturers to obtain and deploy the necessary patches to prevent potential local privilege escalation and maintain device integrity.

More Qualcomm CVEs

Sources