CVE-2025-47356

7.8

Qualcomm · Snapdragon

A memory corruption vulnerability exists in various Qualcomm Snapdragon components due to improper handling of concurrent thread access to shared resources.

Executive summary

A critical memory corruption flaw in multiple Qualcomm Snapdragon products allows local attackers with low privileges to potentially achieve full system compromise.

Vulnerability

The vulnerability is categorized as a double free (CWE-415), triggered when multiple threads concurrently access and modify shared memory resources. Exploitation requires the attacker to have local access and low privileges on the affected hardware.

Business impact

The CVSS score of 7.8 signifies a high-severity risk, primarily due to the potential for total loss of confidentiality, integrity, and availability. Successful exploitation could allow an attacker to execute arbitrary code or cause system instability, leading to unauthorized data access or denial of service on mobile or embedded devices.

Remediation

Immediate Action: Review the official Qualcomm January 2026 security bulletin and apply the relevant firmware or driver updates provided by the device manufacturer.

Proactive Monitoring: Monitor system logs for unusual kernel panics or repeated service crashes that may indicate exploitation attempts targeting memory corruption.

Compensating Controls: Ensure that device security policies are strictly enforced to restrict physical and local access to authorized users only, reducing the likelihood of a local attacker triggering the flaw.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high impact of memory corruption flaws, organizations and end users should prioritize the identification of affected Snapdragon hardware. It is imperative to monitor for and apply vendor-supplied patches as soon as they become available to mitigate the risk of local exploitation.

More Qualcomm CVEs

Sources