CVE-2025-47318
7.5Qualcomm · Snapdragon
A buffer over-read vulnerability exists in Qualcomm Snapdragon chipsets during the parsing of EPTM test control messages, which can lead to a transient denial of service.
Executive summary
A high-severity buffer over-read vulnerability in Qualcomm Snapdragon processors allows unauthenticated attackers to cause a transient denial of service condition.
Vulnerability
The vulnerability is a buffer over-read (CWE-126) triggered during the parsing of EPTM test control messages. The CVSS vector indicates that this flaw is reachable over the network by an unauthenticated attacker.
Business impact
The potential for a denial of service attack poses a significant risk to system availability and reliability. Given the CVSS score of 7.5, this vulnerability is classified as high severity, as it can disrupt critical functions in devices utilizing these Snapdragon components without requiring user interaction or prior authentication.
Remediation
Immediate Action: Review the official Qualcomm security bulletin for September 2025 and apply relevant firmware or driver updates provided by the device manufacturer.
Proactive Monitoring: Monitor system logs for unexpected crashes, reboots, or error messages related to EPTM processing or memory management.
Compensating Controls: Ensure that network traffic to affected devices is strictly controlled via perimeter firewalls to limit exposure to untrusted sources, if applicable to the deployment environment.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing devices equipped with the affected Qualcomm Snapdragon chipsets should prioritize the identification of vulnerable hardware within their inventory. While there is no current evidence of active exploitation, the ability for an unauthenticated attacker to cause a denial of service necessitates prompt attention once the specific vendor patches are released for individual product lines.