CVE-2025-47320

7.8

Qualcomm · Snapdragon

A memory corruption vulnerability exists in Qualcomm Snapdragon chipsets during the processing of MFC channel configurations, which may allow for out-of-bounds writes during music playback.

Executive summary

A critical memory corruption vulnerability in various Qualcomm Snapdragon chipsets poses a significant risk of local system compromise and arbitrary code execution.

Vulnerability

This is an out-of-bounds write vulnerability (CWE-787) triggered by improper handling of MFC channel configuration data during music playback, requiring low-privileged local user access.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high severity risk. Successful exploitation allows a local attacker to achieve total impact on confidentiality, integrity, and availability, potentially leading to full system compromise or persistent unauthorized access on affected hardware.

Remediation

Immediate Action: Monitor the Qualcomm security bulletin portal for the release of firmware updates and apply them to all affected hardware components immediately upon availability.

Proactive Monitoring: Review system and application logs for signs of anomalous crashes or unexpected behavior during media playback processes.

Compensating Controls: Restrict local user access permissions on devices utilizing these chipsets to minimize the potential for an attacker to execute the malicious code required to trigger the flaw.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the nature of the vulnerability, organizations should treat this as a high-priority issue. Administrators must track the vendor's official security bulletin and prioritize patching the affected Snapdragon chipsets as soon as the firmware updates are distributed by the device manufacturers.

More Qualcomm CVEs

Sources