CVE-2025-27061

7.8

Qualcomm · Snapdragon

A memory corruption vulnerability exists in Qualcomm Snapdragon components during the processing of video packets from firmware, potentially allowing for arbitrary code execution or system instability.

Executive summary

A high-severity out-of-bounds write vulnerability in multiple Qualcomm Snapdragon products poses a significant risk of system compromise and memory corruption.

Vulnerability

This is an out-of-bounds write vulnerability (CWE-787) triggered during the parsing of video packets received from the video firmware. The attack requires local access and low privileges to execute.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high level of severity due to the potential for total loss of confidentiality, integrity, and availability. Successful exploitation could lead to unauthorized code execution on the affected hardware, resulting in data theft, persistent system compromise, or complete device denial of service.

Remediation

Immediate Action: Consult the official Qualcomm security bulletin for July 2025 to identify and apply the necessary firmware or driver updates for your specific hardware components.

Proactive Monitoring: Monitor system logs for unusual crashes or error messages related to the video subsystem, which may indicate attempted exploitation of memory corruption flaws.

Compensating Controls: Since this is a low-level firmware vulnerability, ensure that device access is strictly controlled and that only authorized processes have the necessary privileges to interact with the video firmware subsystem.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of memory corruption vulnerabilities in hardware firmware, organizations utilizing the affected Snapdragon components must prioritize reviewing the vendor security bulletin. Apply all recommended firmware updates immediately to prevent potential exploitation and ensure the continued integrity of the device environment.

More Qualcomm CVEs

Sources