CVE-2025-47353

7.8

Qualcomm · Snapdragon

A memory corruption vulnerability exists within Qualcomm Snapdragon components when processing requests sent from a Guest Virtual Machine (GVM).

Executive summary

A high-severity memory corruption vulnerability in Qualcomm Snapdragon processors could allow a local attacker with low privileges to achieve full system impact.

Vulnerability

This vulnerability involves memory corruption triggered during the processing of requests originating from a GVM, classified under CWE-749 as an exposed dangerous method or function. Successful exploitation requires the attacker to possess low-level local privileges.

Business impact

The potential for memory corruption poses a significant risk to system integrity, confidentiality, and availability. Given the CVSS score of 7.8, this vulnerability is categorized as high severity, indicating that a successful exploit could result in unauthorized data access or complete compromise of the affected device.

Remediation

Immediate Action: Review the official Qualcomm security bulletin for November 2025 and apply the relevant firmware or software updates provided by your device manufacturer.

Proactive Monitoring: Monitor system logs for unusual crashes or unexpected behavior related to GVM communication and inter-process requests.

Compensating Controls: Implement strict access controls for GVM environments and ensure that only authorized users or processes can interact with the affected Snapdragon components.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a substantial risk to systems utilizing the affected Qualcomm Snapdragon chipsets. Administrators should prioritize the identification of these specific processor versions within their environment and prepare to deploy vendor-supplied security updates as soon as they become available to mitigate the risk of unauthorized system compromise.

More Qualcomm CVEs

Sources