CVE-2025-47391
7.8Qualcomm · Snapdragon
A stack-based buffer overflow in Qualcomm Snapdragon platforms allows for potential memory corruption when processing frame requests from a local user.
Executive summary
A stack-based buffer overflow vulnerability in Qualcomm Snapdragon hardware components poses a high risk of local privilege escalation or system compromise.
Vulnerability
This vulnerability is a stack-based buffer overflow (CWE-121) occurring during the processing of frame requests, which can be triggered by a local authenticated user with low privileges.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high severity level that could lead to full system compromise, including the loss of confidentiality, integrity, and availability. Because this flaw allows for memory corruption, an attacker could potentially execute arbitrary code on the affected hardware, leading to unauthorized access to sensitive data or complete denial of service for the device.
Remediation
Immediate Action: Review the April 2026 Qualcomm security bulletin and apply all firmware or driver updates provided by the device manufacturer for the affected Snapdragon platforms.
Proactive Monitoring: Monitor system logs for unusual crashes or unexpected service restarts that may indicate attempted memory corruption or buffer overflow activity.
Compensating Controls: Restrict local user permissions where possible to minimize the attack surface, and ensure that only trusted applications are permitted to interact with low-level hardware interfaces.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the nature of the vulnerability within core hardware components, organizations should prioritize the deployment of vendor-supplied patches as soon as they become available. Failure to address this vulnerability leaves systems susceptible to local attacks that could result in total system compromise.