CVE-2025-27070
7.8Qualcomm · Snapdragon (AR8035, FastConnect 6200, FastConnect 6700, FastConnect 6800, FastConnect 6900, FastConnect 7800, QAM8255P, QAM8295P)
A memory corruption vulnerability exists in various Qualcomm Snapdragon components during encryption and decryption operations, potentially leading to unauthorized system impact.
Executive summary
A critical out-of-bounds write vulnerability in multiple Qualcomm Snapdragon products allows a local attacker with low privileges to achieve full system compromise.
Vulnerability
This is an out-of-bounds write (CWE-787) flaw triggered during encryption and decryption commands. The CVSS vector (AV:L/PR:L/UI:N) indicates that an authenticated user with low local privileges is required to trigger the memory corruption.
Business impact
The vulnerability carries a CVSS score of 7.8, which classifies it as High severity. Successful exploitation could allow a local attacker to execute arbitrary code or cause system instability, leading to a total loss of confidentiality, integrity, and availability for the affected hardware.
Remediation
Immediate Action: Review the official Qualcomm November 2025 security bulletin and apply all firmware or driver updates provided for the specific Snapdragon hardware in your environment.
Proactive Monitoring: Monitor system logs for repeated service crashes or unexpected process terminations associated with encryption-related modules.
Compensating Controls: Restrict local access to the affected devices and ensure that only authorized users have the capability to execute commands that interface directly with the affected hardware components.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for total system compromise, organizations should prioritize the identification of affected Snapdragon hardware within their infrastructure. Once the vendor releases specific patches for your device firmware, they should be deployed immediately to mitigate the risk of local privilege escalation and potential code execution.