CVE-2025-27076

7.8

Qualcomm · Snapdragon (AQT1000, FastConnect 6200, 6700, 6800, 6900, 7800, QCA6391, QCA6420)

A time-of-check time-of-use race condition in Qualcomm Snapdragon components allows for memory corruption when processing simultaneous requests via an escape path.

Executive summary

A memory corruption vulnerability in various Qualcomm Snapdragon products poses a high risk of local privilege escalation or system instability due to a race condition.

Vulnerability

This is a Time-of-check Time-of-use (TOCTOU) race condition (CWE-367) occurring within the memory management logic. The vulnerability requires a local attacker with low privileges to trigger concurrent requests that result in memory corruption.

Business impact

Successful exploitation allows a local attacker to achieve high impact on confidentiality, integrity, and availability. With a CVSS score of 7.8, this flaw represents a significant risk to device security, potentially leading to unauthorized data access or complete system compromise. Given the prevalence of these chipsets in mobile and networking hardware, the impact could extend to a broad range of enterprise and consumer devices.

Remediation

Immediate Action: Consult the official Qualcomm August 2025 Security Bulletin to identify and apply the specific firmware or driver updates corresponding to your hardware.

Proactive Monitoring: Monitor system logs for unusual crash patterns or unexpected service restarts, which may indicate exploitation attempts targeting memory corruption.

Compensating Controls: Ensure that device access controls remain strictly enforced to limit the capability of local, low-privileged users to execute unauthorized code or manipulate system processes.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The vulnerability is rated as High severity due to its potential for total impact on the affected system. Organizations utilizing devices equipped with the listed Qualcomm chipsets must prioritize the deployment of vendor-supplied firmware updates as soon as they become available. Until patches are applied, restrict local access to sensitive hardware components to prevent exploitation by malicious actors.

More Qualcomm CVEs

Sources