CVE-2025-47388

7.8

Qualcomm · Snapdragon and Video Collaboration Platforms

A memory corruption vulnerability exists in Qualcomm components due to improper handling of unaligned page addresses during DSP operations.

Executive summary

A memory corruption vulnerability in multiple Qualcomm Snapdragon and Video Collaboration platforms poses a risk of local code execution and system compromise.

Vulnerability

This is a memory corruption flaw (CWE-120) triggered when passing memory pages to a Digital Signal Processor (DSP) with an unaligned starting address. The CVSS vector indicates that a local attacker with low privileges can achieve total confidentiality, integrity, and availability impact.

Business impact

The potential for memory corruption leading to unauthorized code execution or system instability is significant. With a CVSS score of 7.8, this high-severity vulnerability could allow an attacker to bypass security controls, leading to potential data exfiltration or denial of service within the affected hardware environment.

Remediation

Immediate Action: Consult the official January 2026 Qualcomm security bulletin to identify specific firmware or driver updates for the affected hardware modules and apply them as directed.

Proactive Monitoring: Monitor system logs for unexpected reboots, kernel panics, or abnormal hardware behavior that may indicate exploitation attempts against the DSP interface.

Compensating Controls: Restrict local access to the affected devices and ensure that only authorized users or processes have the permissions required to interact with low-level hardware interfaces.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the critical nature of hardware-level memory corruption, administrators should prioritize evaluating their exposure across all identified Qualcomm platforms. Apply vendor-provided patches as soon as they become available to prevent potential local exploitation.

More Qualcomm CVEs

Sources