CVE-2025-47353
7.8Qualcomm · Snapdragon
A memory corruption vulnerability exists within Qualcomm Snapdragon components when processing requests sent from a Guest Virtual Machine (GVM).
Executive summary
A high-severity memory corruption vulnerability in Qualcomm Snapdragon processors could allow a local attacker with low privileges to achieve full system impact.
Vulnerability
This vulnerability involves memory corruption triggered during the processing of requests originating from a GVM, classified under CWE-749 as an exposed dangerous method or function. Successful exploitation requires the attacker to possess low-level local privileges.
Business impact
The potential for memory corruption poses a significant risk to system integrity, confidentiality, and availability. Given the CVSS score of 7.8, this vulnerability is categorized as high severity, indicating that a successful exploit could result in unauthorized data access or complete compromise of the affected device.
Remediation
Immediate Action: Review the official Qualcomm security bulletin for November 2025 and apply the relevant firmware or software updates provided by your device manufacturer.
Proactive Monitoring: Monitor system logs for unusual crashes or unexpected behavior related to GVM communication and inter-process requests.
Compensating Controls: Implement strict access controls for GVM environments and ensure that only authorized users or processes can interact with the affected Snapdragon components.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a substantial risk to systems utilizing the affected Qualcomm Snapdragon chipsets. Administrators should prioritize the identification of these specific processor versions within their environment and prepare to deploy vendor-supplied security updates as soon as they become available to mitigate the risk of unauthorized system compromise.