CVE-2025-47379

7.8

Qualcomm · Snapdragon 5G Fixed Wireless Access Platform and associated chipsets

A memory corruption vulnerability exists in various Qualcomm Snapdragon products due to improper synchronization during concurrent shared buffer access, potentially leading to a use-after-free condition.

Executive summary

A high-severity use-after-free vulnerability in multiple Qualcomm Snapdragon chipsets could allow a local authenticated attacker to achieve full system compromise.

Vulnerability

This flaw is a Use-After-Free (CWE-416) triggered by improper synchronization between buffer assignment and deallocation. It requires a local attacker with low privileges to interact with the shared buffer.

Business impact

Successful exploitation of this vulnerability can lead to unauthorized information disclosure, data integrity loss, and system availability impact. Given the CVSS score of 7.8, this represents a significant risk to the security of affected hardware components, particularly in environments where local access is possible.

Remediation

Immediate Action: Consult the March 2026 Qualcomm security bulletin for specific firmware updates and apply them to all affected hardware components as soon as they are made available.

Proactive Monitoring: Monitor system logs for unusual crashes or instability, which may indicate attempted exploitation of memory corruption flaws.

Compensating Controls: Restrict physical and logical local access to the affected devices to minimize the risk of a low-privileged user triggering the vulnerability.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a high risk for devices utilizing the affected Qualcomm chipsets. Administrators should prioritize the evaluation and deployment of vendor-provided firmware patches once they are released to prevent potential privilege escalation or system instability.

More Qualcomm CVEs

Sources