CVE-2025-27063

7.8

Qualcomm · Snapdragon

A use-after-free vulnerability in Qualcomm Snapdragon hardware allows for memory corruption during video playback if a session open fails due to a timeout error.

Executive summary

A critical memory corruption vulnerability in Qualcomm Snapdragon chipsets could allow local attackers to gain elevated privileges or execute arbitrary code.

Vulnerability

The flaw is a use-after-free (CWE-416) condition triggered during video session initialization. An attacker with local access and low privileges can exploit this memory corruption when a session open request fails due to a timeout, potentially leading to unauthorized system impact.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high severity risk. Successful exploitation could allow a local attacker to compromise the integrity, availability, and confidentiality of the affected hardware platform, potentially leading to full system compromise or persistent unauthorized access.

Remediation

Immediate Action: Review the official Qualcomm December 2025 security bulletin and apply the vendor provided firmware or software updates to all affected Snapdragon platforms.

Proactive Monitoring: Monitor system logs for unexpected video playback crashes or abnormal service behavior that may indicate an attempt to trigger the timeout condition.

Compensating Controls: Since this is a hardware-level vulnerability, minimize local user access to the affected devices and ensure that only trusted applications are permitted to interface with the video hardware.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for complete system impact via memory corruption, immediate action is required to patch affected Qualcomm Snapdragon components. Organizations should prioritize firmware updates for all deployed hardware listed in the vendor advisory to eliminate the risk of exploitation.

More Qualcomm CVEs

Sources