CVE-2025-47389
7.8Qualcomm · Snapdragon
A memory corruption vulnerability exists in various Qualcomm Snapdragon components, stemming from an integer overflow during the generation of attestation reports.
Executive summary
A critical memory corruption vulnerability in Qualcomm Snapdragon components poses a high risk of local system compromise and unauthorized code execution.
Vulnerability
The flaw is categorized as a buffer copy operation failure caused by an integer overflow (CWE-120). An attacker with local, low-privileged access can trigger this condition during attestation report generation to achieve memory corruption.
Business impact
The CVSS score of 7.8 reflects a high-severity risk to system integrity, confidentiality, and availability. Successful exploitation allows a local attacker to potentially execute arbitrary code with elevated privileges, which could lead to full device compromise, sensitive data exfiltration, or persistent denial of service conditions.
Remediation
Immediate Action: Review the April 2026 Qualcomm Security Bulletin for specific firmware or driver updates and apply them to all affected Snapdragon hardware immediately.
Proactive Monitoring: Monitor system logs for unusual crash reports or attestation service failures that may indicate an attempt to trigger the overflow condition.
Compensating Controls: Since this vulnerability requires local access, enforce strict physical security and limit user privilege levels to minimize the attack surface on devices containing the vulnerable chipsets.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for total system compromise, organizations using devices equipped with the affected Qualcomm Snapdragon chipsets should prioritize identifying these assets within their inventory. Once identified, apply the necessary vendor-provided firmware updates as soon as they become available to eliminate the underlying memory corruption risk.