CVE-2025-47342
7.1Qualcomm · Snapdragon and Sound Platforms
A use after free vulnerability in Qualcomm Snapdragon and Sound platforms allows a local authenticated attacker to cause a denial of service or partial integrity impact via multi-profile concurrency.
Executive summary
A use after free vulnerability in Qualcomm platforms, identified as CVE-2025-47342, poses a significant risk for denial of service and potential system instability.
Vulnerability
This vulnerability is a use after free (CWE-416) flaw occurring when multi-profile concurrency is enabled with QHS. The attack requires low privileges to trigger, potentially leading to service disruption or unauthorized state changes.
Business impact
The exploitation of this vulnerability can result in a denial of service, causing system instability or crashes that disrupt critical audio or processing functions. With a CVSS score of 7.1, the vulnerability is classified as High severity, indicating that while it may not be easily automatable, the impact on availability is significant for affected enterprise and consumer hardware.
Remediation
Immediate Action: Review the October 2025 Qualcomm Security Bulletin and apply the latest firmware updates provided by your device manufacturer.
Proactive Monitoring: Monitor system logs for unexpected reboots or service crashes that coincide with concurrent profile usage or high-load scenarios.
Compensating Controls: Limit access to device configuration settings to authorized personnel only to reduce the likelihood of malicious actors triggering concurrent profile states.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the High severity rating and the potential for system-wide denial of service, organizations should prioritize the deployment of vendor-supplied firmware updates. Ensure that all affected Qualcomm-based hardware is tracked in your asset inventory and that update cycles are accelerated for critical infrastructure components.