CVE-2025-47354

7.8

Qualcomm · Snapdragon

A use after free vulnerability in the Qualcomm Snapdragon DSP service allows for memory corruption during buffer allocation.

Executive summary

A critical use after free vulnerability in the Qualcomm Snapdragon DSP service could allow a local attacker with low privileges to achieve full system compromise.

Vulnerability

This vulnerability involves a use after free condition (CWE-416) within the DSP service buffer allocation process. The CVSS vector of AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates that an attacker must have local access and low-level privileges to trigger this flaw.

Business impact

The potential for memory corruption and subsequent arbitrary code execution poses a severe risk to device integrity and user data privacy. Given the CVSS score of 7.8, this vulnerability is classified as High severity, as successful exploitation could lead to total loss of confidentiality, integrity, and availability of the affected system.

Remediation

Immediate Action: Consult the official Qualcomm October 2025 security bulletin to identify specific firmware updates for your device and apply them immediately.

Proactive Monitoring: Monitor system logs for unexpected crashes or service restarts within the DSP subsystem that may indicate exploitation attempts.

Compensating Controls: Ensure that device access controls are strictly enforced to minimize the number of local users with the permissions required to interact with low-level DSP services.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Given the severity of this memory corruption vulnerability, administrators and device owners should prioritize the installation of vendor-supplied firmware updates as soon as they become available. Failure to patch these Snapdragon components leaves systems exposed to potential privilege escalation and unauthorized code execution.

More Qualcomm CVEs

Sources