CVE-2025-47360

7.8

Qualcomm · Snapdragon

A stack-based buffer overflow in Qualcomm Snapdragon chipsets allows for memory corruption during device management message processing.

Executive summary

A memory corruption vulnerability in multiple Qualcomm Snapdragon products creates a high risk of local privilege escalation or system compromise.

Vulnerability

This is a stack-based buffer overflow (CWE-121) occurring during the processing of client messages within the device management component. An attacker with local, low-privileged access can trigger this flaw to achieve total impact on confidentiality, integrity, and availability.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its potential for a complete system compromise. Successful exploitation allows an attacker to execute arbitrary code or cause system instability, which could lead to unauthorized access to sensitive data or the disruption of critical device functions. Given the deep integration of these chipsets into hardware, the impact on affected systems is significant.

Remediation

Immediate Action: Consult the official Qualcomm security bulletin and apply the relevant firmware updates as soon as they are provided by your hardware manufacturer.

Proactive Monitoring: Monitor system logs for unexpected crashes, service restarts, or anomalous memory usage patterns associated with device management processes.

Compensating Controls: Ensure that access to the device is strictly controlled and that only authorized users or processes can interact with the device management interface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical nature of memory corruption vulnerabilities in hardware components, organizations should prioritize patching affected Snapdragon devices. System administrators must work closely with their hardware vendors to track the availability of firmware updates and apply them to all vulnerable units to prevent potential privilege escalation.

More Qualcomm CVEs

Sources