CVE-2025-27055

7.8

Qualcomm · Snapdragon

A buffer over-read vulnerability in Qualcomm Snapdragon components during image encoding may lead to local privilege escalation or system instability.

Executive summary

A memory corruption vulnerability in multiple Qualcomm Snapdragon products allows a local, authenticated attacker to compromise system integrity and availability.

Vulnerability

This vulnerability is a buffer over-read (CWE-126) occurring during the image encoding process. It requires an attacker to have local access with low privileges to trigger the flaw, as indicated by the CVSS vector AV:L/PR:L.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its potential for high impact on confidentiality, integrity, and availability. Successful exploitation allows a local attacker to read memory contents or crash the system, potentially leading to unauthorized data access or denial of service in impacted mobile or networking devices.

Remediation

Immediate Action: Review the July 2025 Qualcomm security bulletin and apply the relevant firmware or driver updates provided by your device manufacturer.

Proactive Monitoring: Monitor system logs for unusual crashes related to image processing services or unexpected process terminations.

Compensating Controls: Ensure that only trusted applications are installed on the device to minimize the risk of a low-privileged user executing malicious code.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the critical nature of firmware-level vulnerabilities, administrators must prioritize the identification of affected hardware in their environment. Once the manufacturer releases the specific patch, it should be deployed immediately to mitigate the risk of local privilege escalation.

More Qualcomm CVEs

Sources