CVE-2025-47355

7.8

Qualcomm · Snapdragon

A memory corruption vulnerability exists in various Qualcomm Snapdragon products due to improper handling of remote procedure IOCTL calls, potentially leading to arbitrary code execution.

Executive summary

A critical memory corruption vulnerability in multiple Qualcomm Snapdragon hardware components may allow a local attacker to achieve system compromise.

Vulnerability

The vulnerability is an out-of-bounds write (CWE-787) triggered during the invocation of remote procedure IOCTL calls. Based on the CVSS vector (PR:L), this flaw requires the attacker to have local low-level privileges on the target system to successfully trigger the corruption.

Business impact

The potential for memory corruption leading to system-level impact presents a significant risk to data confidentiality, integrity, and availability. With a CVSS score of 7.8, this vulnerability is considered high severity, as successful exploitation could allow an attacker to execute arbitrary code or cause a system crash, resulting in unauthorized access or service disruption.

Remediation

Immediate Action: Review the official Qualcomm October 2025 security bulletin and apply the relevant firmware or driver updates provided by the device manufacturer immediately.

Proactive Monitoring: Monitor system logs for unusual IOCTL-related errors or unexpected service restarts that may indicate attempted exploitation of this memory corruption flaw.

Compensating Controls: Ensure that systems are configured to restrict local user access to the minimum required privileges, as this significantly reduces the attack surface for local exploitation vectors.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the critical nature of memory corruption vulnerabilities in hardware components, organizations should prioritize the identification of affected hardware within their fleet. Administrators must track vendor-specific security advisories for the identified Snapdragon components and deploy patches as soon as they are released to prevent potential local privilege escalation and system compromise.

More Qualcomm CVEs

Sources