CVE-2025-47373
7.8Qualcomm · Snapdragon
A memory corruption vulnerability exists in various Qualcomm Snapdragon products due to improper buffer handling during Trusted Application (TA) invocation, potentially leading to system compromise.
Executive summary
A critical out-of-bounds write vulnerability in Qualcomm Snapdragon components enables local attackers to achieve total system compromise.
Vulnerability
This vulnerability is an out-of-bounds write (CWE-787) flaw triggered when accessing buffers with invalid lengths during Trusted Application invocation. The vulnerability requires low privileges (PR:L) and local access (AV:L) to exploit.
Business impact
Successful exploitation of this vulnerability allows an attacker to gain elevated control over the affected hardware platform. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, unauthorized data access, or denial of service, significantly impacting the integrity and availability of the underlying device.
Remediation
Immediate Action: Consult the official Qualcomm March 2026 security bulletin to identify and apply the specific firmware or driver updates for your affected Snapdragon platform.
Proactive Monitoring: Review system and kernel logs for abnormal activity or unexpected crashes associated with Trusted Application execution environments.
Compensating Controls: Implement strict device access controls and ensure that only authorized applications can interact with the Trusted Execution Environment (TEE) to limit the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the severity of memory corruption flaws within hardware-level Trusted Applications, immediate remediation is required. Administrators should prioritize the deployment of vendor-supplied firmware updates to all vulnerable Snapdragon-based devices to neutralize the risk of unauthorized system-wide access.