CVE-2025-47373

7.8

Qualcomm · Snapdragon

A memory corruption vulnerability exists in various Qualcomm Snapdragon products due to improper buffer handling during Trusted Application (TA) invocation, potentially leading to system compromise.

Executive summary

A critical out-of-bounds write vulnerability in Qualcomm Snapdragon components enables local attackers to achieve total system compromise.

Vulnerability

This vulnerability is an out-of-bounds write (CWE-787) flaw triggered when accessing buffers with invalid lengths during Trusted Application invocation. The vulnerability requires low privileges (PR:L) and local access (AV:L) to exploit.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain elevated control over the affected hardware platform. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, unauthorized data access, or denial of service, significantly impacting the integrity and availability of the underlying device.

Remediation

Immediate Action: Consult the official Qualcomm March 2026 security bulletin to identify and apply the specific firmware or driver updates for your affected Snapdragon platform.

Proactive Monitoring: Review system and kernel logs for abnormal activity or unexpected crashes associated with Trusted Application execution environments.

Compensating Controls: Implement strict device access controls and ensure that only authorized applications can interact with the Trusted Execution Environment (TEE) to limit the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the severity of memory corruption flaws within hardware-level Trusted Applications, immediate remediation is required. Administrators should prioritize the deployment of vendor-supplied firmware updates to all vulnerable Snapdragon-based devices to neutralize the risk of unauthorized system-wide access.

More Qualcomm CVEs

Sources