CVE-2025-27075

7.8

Qualcomm · Snapdragon (FastConnect and QCA chipsets)

A memory corruption vulnerability in the Bluetooth Host component allows for potential system impact due to improper validation of array indices when processing IOCTL commands.

Executive summary

A memory corruption flaw in Qualcomm Bluetooth host firmware on various Snapdragon and FastConnect chipsets poses a significant risk of local privilege escalation or system compromise.

Vulnerability

The vulnerability is identified as a memory corruption issue stemming from CWE-129, Improper Validation of Array Index. An attacker with local, low-privileged access can trigger this flaw by sending a specially crafted IOCTL command with an oversized buffer to the Bluetooth Host.

Business impact

The exploitation of this vulnerability could lead to a complete compromise of the affected device, including unauthorized data access, integrity loss, and system instability. With a CVSS score of 7.8, the severity is High because it allows a local attacker to achieve high impact across all three security pillars (Confidentiality, Integrity, and Availability).

Remediation

Immediate Action: Review the official Qualcomm August 2025 security bulletin and apply the firmware updates provided by the respective device manufacturer as soon as they become available.

Proactive Monitoring: Monitor system logs for unexpected Bluetooth service restarts or kernel-level memory faults that may indicate attempts to exploit this memory corruption condition.

Compensating Controls: Ensure that device access is restricted to authorized personnel only, as this vulnerability requires local access to the system to initiate the malicious IOCTL request.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the critical nature of firmware-level vulnerabilities, administrators should prioritize the deployment of vendor-supplied patches as soon as they are released for their specific hardware models. Failure to remediate could allow an attacker with local access to escalate privileges and gain deep control over the affected system.

More Qualcomm CVEs

Sources