CVE-2025-47357
8.0Qualcomm · Snapdragon
A vulnerability in Qualcomm Snapdragon processors allows information disclosure when a user-level driver performs unauthorized QFPROM read or write operations on Fuse regions.
Executive summary
A critical information disclosure vulnerability in multiple Qualcomm Snapdragon products allows unauthorized access to sensitive Fuse regions due to missing authentication.
Vulnerability
This vulnerability is caused by a missing authentication check (CWE-306) for critical functions within the driver interface. The flaw allows an unauthenticated user-level driver to perform read or write operations on QFPROM Fuse regions.
Business impact
The ability to perform unauthorized read or write operations on hardware-level Fuse regions poses a significant security risk, potentially leading to the compromise of device security features or sensitive data. With a CVSS score of 8.0, this high-severity flaw could facilitate persistent unauthorized access or the bypass of hardware-backed security controls. Organizations relying on these Snapdragon components for secure operations face potential integrity and confidentiality risks.
Remediation
Immediate Action: Review the official Qualcomm security bulletin for November 2025 and apply the recommended firmware or driver updates provided by your specific hardware manufacturer.
Proactive Monitoring: Monitor system logs for unusual driver activity or unauthorized attempts to access low-level hardware interfaces.
Compensating Controls: Ensure that only authorized and signed drivers are permitted to load on affected systems to limit the potential for malicious user-level drivers to interact with hardware interfaces.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS severity and the low-level nature of the affected components, immediate attention is required to ensure that all vulnerable Qualcomm Snapdragon firmware is updated. Organizations should prioritize patching cycles for devices using the identified chips to prevent potential exploitation of these critical hardware interfaces.