CVE-2025-47390

7.8

Qualcomm · Snapdragon and Video Collaboration Platforms

A memory corruption vulnerability in the JPEG driver allows local attackers to trigger a buffer over-read during IOCTL request preprocessing.

Executive summary

A critical memory corruption vulnerability in Qualcomm hardware components may allow local attackers with low privileges to achieve elevated system impact.

Vulnerability

This flaw involves a buffer over-read (CWE-126) occurring during the preprocessing of IOCTL requests within the JPEG driver. Successful exploitation requires a local attacker with low privileges to interact with the vulnerable driver, potentially leading to unauthorized information disclosure or system instability.

Business impact

The CVSS score of 7.8 (High) reflects the significant risk posed by this vulnerability despite the local access requirement. Successful exploitation could result in full system compromise, including unauthorized access to sensitive data processed by the JPEG driver or complete service disruption, leading to severe operational downtime and potential data loss.

Remediation

Immediate Action: Review the April 2026 Qualcomm security bulletin for specific firmware or driver updates applicable to your hardware and apply them immediately.

Proactive Monitoring: Monitor system logs for unusual driver activity or frequent process crashes associated with JPEG processing tasks.

Compensating Controls: Implement strict host-based access controls to limit the number of users or processes capable of interacting with hardware-level IOCTL interfaces.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high severity and the nature of hardware-level vulnerabilities, organizations should prioritize updating all affected Qualcomm platforms. Administrators must verify firmware versions against the vendor advisory to ensure complete coverage, as hardware-based flaws often require vendor-specific distribution cycles.

More Qualcomm CVEs

Sources