CVE-2025-47368
7.8Qualcomm · Snapdragon (FastConnect, SC8380XP, WCD9380, WCD9385, WSA8840, WSA8845, WSA8845H)
A buffer over-read vulnerability exists in Qualcomm Snapdragon components due to memory corruption during MCDM IOCTL processing, allowing for potential local privilege escalation.
Executive summary
A memory corruption vulnerability in multiple Qualcomm Snapdragon hardware components may allow a local attacker with low privileges to achieve high impact on confidentiality, integrity, and availability.
Vulnerability
This is a buffer over-read (CWE-126) occurring when the system dereferences an invalid userspace address within a user buffer during MCDM IOCTL processing. The vulnerability requires the attacker to have local access and low-level privileges to interact with the affected IOCTL interface.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high severity risk. Successful exploitation allows a local attacker to compromise the integrity and confidentiality of the system, potentially leading to unauthorized data access or system instability. Given that these components are integrated into mobile and computing hardware, this flaw could be leveraged to bypass security boundaries on affected devices.
Remediation
Immediate Action: Review the November 2025 Qualcomm Security Bulletin and apply all relevant firmware or driver updates provided by your device manufacturer.
Proactive Monitoring: Monitor system logs for unusual IOCTL activity or recurring crashes associated with mobile connectivity or audio subsystems.
Compensating Controls: Ensure that device security policies restrict local user access and utilize hardware-backed security features where available to limit the impact of potential local privilege escalation.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this memory corruption flaw necessitates prompt attention from administrators and security teams managing devices using the affected Qualcomm hardware. Prioritize the deployment of vendor-supplied firmware updates as soon as they are made available by OEMs to mitigate the risk of local privilege escalation.