CVE-2025-27074

8.8

Qualcomm · Snapdragon

A memory corruption vulnerability exists in Qualcomm Snapdragon processors during the processing of GP command responses, potentially allowing for arbitrary code execution.

Executive summary

A critical memory corruption vulnerability in Qualcomm Snapdragon processors poses a significant risk of system compromise through local exploitation.

Vulnerability

The vulnerability is categorized as an incorrect calculation of buffer size (CWE-131) occurring during the handling of GP command responses. An attacker with local access and low privileges can trigger this flaw to achieve full system control.

Business impact

Successful exploitation of this memory corruption vulnerability can lead to a complete loss of confidentiality, integrity, and availability. With a CVSS score of 8.8, this flaw represents a high-severity risk that could result in unauthorized administrative access or system-wide instability. Organizations relying on affected Snapdragon-based hardware may face significant operational downtime and potential data exposure if an attacker gains local execution capabilities.

Remediation

Immediate Action: Consult the official Qualcomm November 2025 Security Bulletin to identify and apply the necessary firmware or driver updates for your specific hardware platform.

Proactive Monitoring: Monitor system logs for unusual kernel activity, unexpected reboots, or segmentation faults that may indicate attempts to trigger memory corruption.

Compensating Controls: Restrict physical or local access to systems utilizing these processors, as the vulnerability requires local access to execute the exploit.

Exploitation status

Public Exploit Available: No (Unknown)

Analyst recommendation

This vulnerability presents a severe risk to the integrity of the underlying hardware platform. Security teams must prioritize the verification of patch availability through the official Qualcomm security portal and expedite the deployment of firmware updates to all affected devices to eliminate the underlying memory calculation error.

More Qualcomm CVEs

Sources