CVE-2025-27077

7.8

Qualcomm · Snapdragon

A use-after-free memory corruption vulnerability exists in various Qualcomm Snapdragon processors when processing messages within a guest virtual machine.

Executive summary

A high-severity memory corruption vulnerability in Qualcomm Snapdragon processors allows an authenticated local attacker to achieve total system compromise.

Vulnerability

This vulnerability is a use-after-free flaw (CWE-416) that occurs during message processing in a guest virtual machine, requiring low-privileged access to the local system to execute.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high risk of total impact to confidentiality, integrity, and availability. Successful exploitation could allow a local attacker to escalate privileges or execute arbitrary code within the processor environment, potentially leading to a complete compromise of the affected hardware and sensitive data stored therein.

Remediation

Immediate Action: Review the official Qualcomm security bulletin for September 2025 and apply the relevant firmware or software patches as soon as they are made available by your device manufacturer.

Proactive Monitoring: Monitor system logs for unusual crashes, kernel panics, or unexpected reboots that may indicate a memory corruption event or attempted exploitation of the guest VM interface.

Compensating Controls: Implement strict access control policies to limit user privileges on systems utilizing these processors, thereby reducing the likelihood of an attacker obtaining the low-level access required to trigger this flaw.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

Given the potential for total system compromise and the high CVSS severity, organizations utilizing the affected Snapdragon chipsets must prioritize the deployment of vendor security updates. Administrators should maintain a rigorous patch management cycle and restrict user access to the lowest necessary level to mitigate the risk posed by this use-after-free vulnerability.

More Qualcomm CVEs

Sources