CVE-2025-27060
8.8Qualcomm · Snapdragon (Immersive Home Platforms and IPQ/QCN chipsets)
A memory corruption vulnerability exists in Qualcomm Snapdragon chipsets due to improper handling of SCM calls with malformed inputs, potentially allowing unauthorized system operations.
Executive summary
A high-severity memory corruption vulnerability in Qualcomm Snapdragon platforms may allow local attackers with low privileges to achieve full system compromise.
Vulnerability
This vulnerability is a result of an untrusted pointer dereference (CWE-822) triggered during Secure Channel Manager (SCM) calls. An attacker with low privileges can provide malformed inputs to the SCM interface to corrupt system memory, which may lead to arbitrary code execution within the secure context.
Business impact
The CVSS score of 8.8 indicates a high risk to business operations, as successful exploitation results in total system impact, including loss of confidentiality, integrity, and availability. Compromise of these chipsets could allow an attacker to bypass security boundaries, potentially leading to persistent device control or unauthorized access to sensitive data processed within the Qualcomm platform environment.
Remediation
Immediate Action: Review the October 2025 Qualcomm Security Bulletin and coordinate with your hardware manufacturer or OEM to obtain and apply the necessary firmware or driver updates.
Proactive Monitoring: Monitor system logs for unusual kernel panics, unexpected reboots, or unauthorized attempts to access low-level system interfaces.
Compensating Controls: Ensure that device access is strictly controlled, limiting the ability for unauthorized users or processes to interact with the SCM interface, and maintain strict physical security for hardware devices.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a severe risk due to the potential for total system compromise within the affected Qualcomm Snapdragon chipsets. IT and security teams should prioritize identifying vulnerable hardware within their environment and engage with their vendors to ensure that firmware updates are deployed as soon as they become available.