CVE-2025-47388
7.8Qualcomm · Snapdragon and Video Collaboration Platforms
A memory corruption vulnerability exists in Qualcomm components due to improper handling of unaligned page addresses during DSP operations.
Executive summary
A memory corruption vulnerability in multiple Qualcomm Snapdragon and Video Collaboration platforms poses a risk of local code execution and system compromise.
Vulnerability
This is a memory corruption flaw (CWE-120) triggered when passing memory pages to a Digital Signal Processor (DSP) with an unaligned starting address. The CVSS vector indicates that a local attacker with low privileges can achieve total confidentiality, integrity, and availability impact.
Business impact
The potential for memory corruption leading to unauthorized code execution or system instability is significant. With a CVSS score of 7.8, this high-severity vulnerability could allow an attacker to bypass security controls, leading to potential data exfiltration or denial of service within the affected hardware environment.
Remediation
Immediate Action: Consult the official January 2026 Qualcomm security bulletin to identify specific firmware or driver updates for the affected hardware modules and apply them as directed.
Proactive Monitoring: Monitor system logs for unexpected reboots, kernel panics, or abnormal hardware behavior that may indicate exploitation attempts against the DSP interface.
Compensating Controls: Restrict local access to the affected devices and ensure that only authorized users or processes have the permissions required to interact with low-level hardware interfaces.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the critical nature of hardware-level memory corruption, administrators should prioritize evaluating their exposure across all identified Qualcomm platforms. Apply vendor-provided patches as soon as they become available to prevent potential local exploitation.