CVE-2025-47349

7.8

Qualcomm · Snapdragon

A memory corruption vulnerability exists in multiple Qualcomm Snapdragon components due to the improper handling of escape calls, potentially leading to unauthorized data access or system compromise.

Executive summary

A critical memory corruption vulnerability in various Qualcomm Snapdragon products poses a significant risk of local privilege escalation and system compromise.

Vulnerability

This vulnerability involves the use of an out-of-range pointer offset (CWE-823) during the processing of an escape call. The vulnerability requires local access with low privileges to trigger the flaw, as indicated by the CVSS vector AV:L/PR:L.

Business impact

The potential for memory corruption allows an attacker to manipulate system memory, which can lead to a full compromise of confidentiality, integrity, and availability. With a CVSS score of 7.8, this flaw represents a high-severity risk to business operations, as it could allow unauthorized users to gain elevated system privileges and bypass security controls.

Remediation

Immediate Action: Review the official Qualcomm security bulletin for October 2025 and apply all relevant firmware or driver updates provided by your device manufacturer.

Proactive Monitoring: Monitor system logs for unusual crash patterns or unexpected behavior in kernel-level processes that may indicate an exploitation attempt.

Compensating Controls: Ensure that systems are running with restricted user permissions to prevent unauthorized processes from gaining the low-level access required to trigger this vulnerability.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the technical impact and the severity of memory corruption vulnerabilities in hardware components, administrators should prioritize the deployment of vendor-supplied firmware updates. Users and organizations should track the release status of patches for the specific affected Snapdragon components listed to ensure comprehensive mitigation across their device fleet.

More Qualcomm CVEs

Sources