CVE-2025-47361

7.8

Qualcomm · Snapdragon (QAM8255P, QAM8295P, QAM8620P, QAM8650P, QAM8775P, QAMSRV1H, QAMSRV1M, QCA6574AU)

A memory corruption vulnerability exists in multiple Qualcomm Snapdragon products due to improper validation of array indices, which can be triggered by a subsystem crash.

Executive summary

A high-severity memory corruption vulnerability in various Qualcomm Snapdragon processors allows local attackers to potentially achieve full system compromise.

Vulnerability

The vulnerability is classified as CWE-129 (Improper Validation of Array Index), which occurs when an out-of-range identifier triggers a subsystem crash, leading to memory corruption. This exploit requires low privileges and local access to the system.

Business impact

The CVSS score of 7.8 indicates a high-severity risk, primarily due to the potential for total impact on confidentiality, integrity, and availability. Successful exploitation could allow a local attacker to execute arbitrary code with elevated privileges, resulting in complete system compromise and potential unauthorized access to sensitive data processed by the affected Snapdragon components.

Remediation

Immediate Action: Review the November 2025 Qualcomm Security Bulletin and apply the recommended firmware or driver updates provided by your device manufacturer.

Proactive Monitoring: Monitor system logs for unexpected subsystem crashes or recurring service restarts that may indicate an attempt to trigger this memory corruption condition.

Compensating Controls: Ensure that access to the device is restricted to authorized personnel only, as the vulnerability requires local access to the affected hardware.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for high-impact system compromise, organizations using devices with the specified Qualcomm Snapdragon chipsets must prioritize the deployment of vendor security updates. Administrators should track the official Qualcomm security bulletin and coordinate with device OEMs to ensure patches are applied as soon as they are made available for specific hardware configurations.

More Qualcomm CVEs

Sources