CVE-2025-47345

8.4

Qualcomm, Inc. · Snapdragon (AR8035, FastConnect series, QAM series)

A cryptographic vulnerability exists in various Qualcomm Snapdragon components, where the reuse of nonces or key pairs during license data encryption may lead to data compromise.

Executive summary

A cryptographic flaw in multiple Qualcomm Snapdragon hardware components poses a high risk of unauthorized information disclosure due to improper key management.

Vulnerability

The vulnerability, classified as CWE-323, involves the reuse of a nonce or key pair during the encryption process. The CVSS vector indicates that a local attacker with low privileges can achieve significant confidentiality and integrity impacts.

Business impact

The exploitation of this cryptographic weakness could allow an attacker to decrypt sensitive license data or potentially manipulate encrypted communications. Given the CVSS score of 8.4, this vulnerability is considered High severity, as it threatens the core security foundation of the affected hardware platforms. Failure to address this could lead to the exposure of proprietary information or loss of integrity in secure boot and licensing processes.

Remediation

Immediate Action: Organizations should consult the January 2026 Qualcomm security bulletin and apply the relevant firmware or driver updates as soon as they are made available by the device manufacturer.

Proactive Monitoring: Security teams should monitor system logs for unusual cryptographic errors or abnormal process behavior originating from the affected Qualcomm components.

Compensating Controls: Ensure that sensitive data is protected by secondary encryption layers or restricted access controls that do not rely solely on the underlying hardware encryption mechanisms.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the critical nature of cryptographic flaws in hardware components, administrators must prioritize identifying devices in their environment that utilize the listed Qualcomm Snapdragon chipsets. Once the vendor releases the necessary patches, they should be deployed immediately to prevent potential exploitation of the cryptographic weakness.

Sources