CVE-2025-47322

7.8

Qualcomm · Snapdragon

A use-after-free vulnerability in the Qualcomm Snapdragon platform allows for memory corruption during the processing of IOCTL calls.

Executive summary

A high-severity memory corruption vulnerability in Qualcomm Snapdragon hardware could allow a local attacker with low privileges to achieve full system compromise.

Vulnerability

This vulnerability is a use-after-free (CWE-416) flaw triggered during the handling of IOCTL calls to set modes. The CVSS vector (AV:L/AC:L/PR:L) confirms that an attacker must possess low-level local access to the system to exploit this condition.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its potential for total impact on confidentiality, integrity, and availability. Successful exploitation could lead to privilege escalation or arbitrary code execution, potentially resulting in complete system takeover, unauthorized access to sensitive data, or persistent denial of service.

Remediation

Immediate Action: Consult the official Qualcomm December 2025 Security Bulletin to identify specific firmware or driver updates for the affected hardware components.

Proactive Monitoring: Monitor system logs for unusual kernel-level activity or repeated process crashes that may indicate exploitation attempts targeting IOCTL interfaces.

Compensating Controls: Implement strict device access controls and ensure that only authorized users or processes can interact with low-level hardware drivers.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the severity of this memory corruption flaw and its potential for full system control, administrators should prioritize the review of the Qualcomm December 2025 security bulletin. Apply all recommended firmware and driver updates as soon as they are validated for your environment to neutralize this risk.

More Qualcomm CVEs

Sources