CVE-2025-47348

7.8

Qualcomm · Snapdragon

A memory corruption vulnerability in Qualcomm Snapdragon products occurs during identity credential processing, stemming from the use of an uninitialized variable.

Executive summary

A memory corruption vulnerability in various Qualcomm Snapdragon components poses a significant risk of total system compromise for local, authenticated attackers.

Vulnerability

The vulnerability is a memory corruption flaw resulting from the use of an uninitialized variable (CWE-457) during identity credential operations. It requires an attacker to possess local, low-level privileges to successfully trigger the flaw.

Business impact

The exploitation of this vulnerability allows for unauthorized access, potentially leading to full system compromise, including the loss of confidentiality, integrity, and availability. With a CVSS score of 7.8, the vulnerability is classified as High severity, reflecting the critical impact on the affected device security posture. Successful exploitation could allow attackers to bypass security controls or execute arbitrary code within the context of the trusted application.

Remediation

Immediate Action: Review the official January 2026 Qualcomm security bulletin and apply the relevant firmware or driver updates provided by your device manufacturer.

Proactive Monitoring: Monitor system logs for unexpected crashes or error messages related to identity credential services and trusted applications.

Compensating Controls: Ensure device integrity protections, such as Secure Boot and hardware-backed keystores, are fully enabled to limit the potential scope of an exploit.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for total system impact and the nature of memory corruption vulnerabilities, this issue should be prioritized for remediation. IT administrators and security teams should track manufacturer update releases for the affected Snapdragon chipsets and apply patches immediately upon availability to ensure device security and integrity.

More Qualcomm CVEs

Sources