CVE-2025-47367

7.8

Qualcomm · Snapdragon

A memory corruption vulnerability exists in Qualcomm Snapdragon components due to improper buffer handling during IOCTL processing, potentially leading to unauthorized system impact.

Executive summary

A critical memory corruption flaw in Qualcomm Snapdragon hardware components allows local attackers with low privileges to potentially gain full system control.

Vulnerability

The vulnerability is an out of bounds write (CWE-787) occurring during input or output control (IOCTL) processing. Successful exploitation requires the attacker to have local access with low privileges to the affected device.

Business impact

The CVSS score of 7.8 (High) reflects the severity of this issue, as successful exploitation can lead to a complete compromise of confidentiality, integrity, and availability. In a business context, this poses a significant risk to device security and data privacy, as an attacker could execute arbitrary code with elevated privileges, leading to unauthorized data access or persistent system instability.

Remediation

Immediate Action: Review the official Qualcomm security bulletin for November 2025 and apply the relevant firmware updates provided by your specific hardware manufacturer or device vendor.

Proactive Monitoring: Monitor system logs for unusual crashes, unexpected reboots, or unauthorized attempts to interface with IOCTL drivers that may indicate exploitation attempts.

Compensating Controls: Ensure that device access is strictly managed and that only authorized users have local access, as this vulnerability requires local interaction to trigger the flaw.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for high-impact system compromise, organizations using affected Qualcomm Snapdragon hardware must prioritize the identification and deployment of vendor firmware patches. Administrators should verify the specific versions within their fleet and coordinate with mobile or hardware vendors to ensure updates are applied as soon as they become available.

More Qualcomm CVEs

Sources