CVE-2025-47377

7.8

Qualcomm · Snapdragon

A use after free vulnerability exists in multiple Qualcomm Snapdragon products when processing IOCTL calls, potentially leading to memory corruption.

Executive summary

A critical use after free vulnerability in multiple Qualcomm Snapdragon platforms poses a significant risk of arbitrary code execution and system instability.

Vulnerability

This is a use after free flaw (CWE-416) triggered during the processing of IOCTL calls, which can allow a locally authenticated attacker with low privileges to corrupt memory.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its potential for complete impact on confidentiality, integrity, and availability. Successful exploitation could allow a malicious actor to gain unauthorized control over the affected hardware, resulting in data theft, service disruption, or total system compromise.

Remediation

Immediate Action: Review the March 2026 Qualcomm security bulletin and apply the necessary firmware or driver updates provided by your device manufacturer.

Proactive Monitoring: Monitor system logs for unusual crashes or IOCTL-related errors that may indicate an attempt to trigger memory corruption.

Compensating Controls: Ensure that access to the affected devices is restricted to authorized users only, as the vulnerability requires local access to the system.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for high impact and the nature of memory corruption vulnerabilities, organizations should prioritize the deployment of vendor-supplied firmware updates as soon as they become available. Failure to patch these components may leave critical hardware platforms susceptible to privilege escalation and persistent exploitation by local attackers.

More Qualcomm CVEs

Sources