CVE-2025-47317

7.8

Qualcomm · Snapdragon (FastConnect and QCC series)

A global buffer overflow in Qualcomm Snapdragon components allows for memory corruption when a test command processes an invalid payload type.

Executive summary

A memory corruption vulnerability in various Qualcomm Snapdragon hardware components poses a high risk of system compromise through local exploitation.

Vulnerability

This vulnerability is a buffer over-read (CWE-126) triggered when the system processes a test command with an malformed payload. Based on the CVSS vector (PR:L), this requires an attacker to possess local low-level privileges on the affected system to trigger the memory corruption.

Business impact

Successful exploitation of this flaw can lead to significant security breaches, including unauthorized access to sensitive data, integrity loss, and potential system crashes. Given the CVSS score of 7.8, this vulnerability is classified as High severity, indicating that while it requires local access, the potential for total impact on confidentiality, integrity, and availability is substantial.

Remediation

Immediate Action: Review the official Qualcomm September 2025 security bulletin and apply the corresponding firmware or driver updates provided by your device manufacturer.

Proactive Monitoring: Monitor system logs for unusual process crashes or unauthorized attempts to interface with hardware-specific test commands or debug interfaces.

Compensating Controls: Restrict access to local interfaces and ensure that only authorized users have the necessary permissions to execute low-level system or hardware commands.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing affected Qualcomm Snapdragon hardware must prioritize the identification of vulnerable devices within their infrastructure. Because this is a hardware-level vulnerability, remediation relies heavily on vendor-supplied firmware updates, which should be tested and deployed as soon as they become available to mitigate the risk of local privilege escalation and system compromise.

More Qualcomm CVEs

Sources