CVE-2025-47380

7.8

Qualcomm · Snapdragon (FastConnect 7800, QCC2072, WCD9378C, WSA8840, WSA8845, WSA8845H, X2000077, X2000086)

A memory corruption vulnerability exists in Qualcomm Snapdragon sensors due to improper handling of IOCTL preprocessing.

Executive summary

A memory corruption vulnerability in multiple Qualcomm Snapdragon hardware components allows local attackers to achieve full system compromise.

Vulnerability

This is an untrusted pointer dereference vulnerability (CWE-822) occurring during the preprocessing of IOCTLs within sensor components. An authenticated local user with low privileges can trigger this flaw to achieve high confidentiality, integrity, and availability impact.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its potential for severe impact on affected devices. Successful exploitation allows an attacker to execute arbitrary code or cause system instability, leading to potential data theft or complete loss of control over the affected hardware component. Because these components are deeply integrated into mobile and IoT ecosystems, this flaw poses a significant risk to device security and user privacy.

Remediation

Immediate Action: Review the official Qualcomm January 2026 Security Bulletin and apply the recommended firmware or driver updates provided by your device manufacturer.

Proactive Monitoring: Monitor device logs for unusual sensor-related crashes or unexpected kernel-level errors that may indicate exploitation attempts.

Compensating Controls: Ensure that device access controls remain strict, as the vulnerability requires local access to the device to trigger the IOCTL processing flaw.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of memory corruption vulnerabilities in hardware components, organizations and end users must prioritize the deployment of firmware updates as soon as they are made available by OEMs. Failure to remediate this issue leaves devices susceptible to local privilege escalation and potential system-wide compromise. Monitor the Qualcomm security portal for specific patch availability for your specific device model.

More Qualcomm CVEs

Sources