CVE-2025-47343

7.8

Qualcomm · Snapdragon and Video Collaboration Platforms

A memory corruption vulnerability exists in multiple Qualcomm platforms during the processing of video session parameters, potentially allowing for unauthorized system impact.

Executive summary

A critical memory corruption vulnerability in various Qualcomm Snapdragon and video platform components poses a significant risk of local system compromise.

Vulnerability

The vulnerability is an untrusted pointer dereference (CWE-822) that occurs during the processing of video session parameters. An attacker with local access and low privileges can trigger this memory corruption to achieve high confidentiality, integrity, and availability impact.

Business impact

The exploitation of this flaw could allow a local attacker to escalate privileges or cause system instability, leading to potential unauthorized data access or a total denial of service on affected hardware. Given the CVSS score of 7.8, this is a high-severity issue that necessitates prompt attention to prevent unauthorized control over critical hardware communication modules.

Remediation

Immediate Action: Review the official Qualcomm January 2026 security bulletin and apply the relevant manufacturer firmware or software updates as soon as they are made available for your specific hardware configuration.

Proactive Monitoring: Monitor system logs for unusual crashes or service restarts associated with video processing modules or hardware communication interfaces.

Compensating Controls: Restrict local access to systems utilizing the affected Qualcomm chipsets to authorized personnel only to mitigate the risk of an attacker gaining the necessary local presence to trigger the flaw.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing devices equipped with the identified Qualcomm chipsets should prioritize identifying these assets within their infrastructure. Because this vulnerability involves deep-level memory corruption, applying vendor-supplied firmware updates is the only definitive path to remediation. Maintain vigilance for additional guidance from device manufacturers regarding the availability of patches for specific end-user products.

More Qualcomm CVEs

Sources