CVE-2025-47316

7.8

Qualcomm · Snapdragon

A double free vulnerability in Qualcomm Snapdragon components allows for local memory corruption due to a race condition when setting the timestamp store.

Executive summary

A memory corruption vulnerability in various Qualcomm Snapdragon products poses a significant risk of local privilege escalation and system compromise.

Vulnerability

This flaw is a double free memory corruption issue (CWE-415) triggered by a race condition between multiple threads. An attacker with local, low-privileged access can exploit this condition to compromise system integrity.

Business impact

Successful exploitation of this vulnerability can lead to unauthorized system access, data corruption, or total service disruption. Given the CVSS score of 7.8, this is a high-severity issue that could allow a local attacker to escalate privileges or execute arbitrary code, potentially leading to a complete compromise of the affected device or host system.

Remediation

Immediate Action: Consult the official September 2025 Qualcomm security bulletin to identify specific firmware updates and apply them to all vulnerable Snapdragon components immediately.

Proactive Monitoring: Review system logs for signs of unexpected process crashes or kernel panics that may indicate memory corruption attempts.

Compensating Controls: Restrict local access to the affected hardware components and ensure that only trusted applications are permitted to execute on the host system to minimize the attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the severity of potential local privilege escalation, organizations using the listed Qualcomm Snapdragon hardware should prioritize the deployment of vendor-supplied patches. Verify the application of security updates through the vendor portal and ensure that all affected firmware versions are brought to a secure state to mitigate the risk of local exploitation.

More Qualcomm CVEs

Sources