CVE-2025-47350

7.8

Qualcomm · Snapdragon

A use-after-free vulnerability in Qualcomm Snapdragon products allows local users to trigger memory corruption via concurrent memory mapping and unmapping requests.

Executive summary

A high-severity use-after-free vulnerability in various Qualcomm Snapdragon components enables local attackers to achieve potential code execution or system instability.

Vulnerability

This is a use-after-free flaw (CWE-416) triggered by race conditions during concurrent memory mapping and unmapping operations. The vulnerability requires local, authenticated access to the system to exploit.

Business impact

The exploitation of this memory corruption vulnerability can lead to unauthorized code execution, privilege escalation, or complete system compromise. Given the CVSS score of 7.8, this flaw poses a significant risk to the integrity and availability of affected devices. Successful exploitation allows an attacker to bypass security boundaries, potentially resulting in sensitive data exposure or persistent system disruption.

Remediation

Immediate Action: Consult the official December 2025 Qualcomm Security Bulletin and apply the latest firmware or driver updates provided by your device manufacturer.

Proactive Monitoring: Monitor system logs for unusual crashes or service restarts that may indicate attempted memory corruption or heap exploitation.

Compensating Controls: Ensure that access to the device is strictly limited to authorized users, as the vulnerability requires local access to the system to be triggered.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a critical security gap in low-level memory management within Qualcomm hardware. Security teams should prioritize identifying affected Snapdragon components within their infrastructure and coordinate with vendors to deploy applicable firmware updates as soon as they become available. Immediate action is required to mitigate the risk of local privilege escalation.

More Qualcomm CVEs

Sources