CVE-2025-47329
7.8Qualcomm · Snapdragon (FastConnect 7800, QAM8255P, QAM8775P, QCA6574, QCA6574A, QCA6574AU, QCA6595, QCA6595AU)
A memory corruption vulnerability exists in Qualcomm Snapdragon chipsets during the processing of invalid inputs within the application info setup function.
Executive summary
A critical memory corruption vulnerability in multiple Qualcomm Snapdragon chipsets could allow a local authenticated attacker to achieve full system compromise.
Vulnerability
The vulnerability is a memory corruption flaw (CWE-763) triggered by improper handling of invalid inputs during application info setup. This requires an attacker to have local access with low-level user privileges to trigger the flaw.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high severity risk. Successful exploitation allows an attacker to gain elevated privileges, potentially resulting in complete confidentiality, integrity, and availability impact on the affected device. This could lead to sensitive data theft, unauthorized system control, or persistent denial of service.
Remediation
Immediate Action: Consult the September 2025 Qualcomm Security Bulletin to identify specific firmware updates for your device and apply them immediately.
Proactive Monitoring: Monitor system logs for unexpected crashes or error patterns associated with the application info setup process, which may indicate exploitation attempts.
Compensating Controls: Implement strict device access controls to minimize the number of local users with the necessary privileges to interact with low-level chipset interfaces.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the nature of memory corruption vulnerabilities within chipset firmware, organizations should prioritize the deployment of firmware updates provided by Qualcomm and downstream device manufacturers. Ensure that all affected Snapdragon-based hardware is patched as soon as the vendor makes the relevant security updates available.