CVE-2025-47394
7.8Qualcomm · Snapdragon and Video Collaboration Platforms
A memory corruption vulnerability exists in multiple Qualcomm platforms due to incorrect offset calculations when copying overlapping buffers.
Executive summary
A memory corruption vulnerability in various Qualcomm Snapdragon and Video Collaboration products poses a high risk of local privilege escalation or system compromise.
Vulnerability
This is a buffer overflow flaw (CWE-120) triggered by improper handling of overlapping memory buffers. Exploitation requires a local attacker with low-level privileges to execute code or cause system instability.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high severity level. Because it allows for memory corruption, a successful exploit could result in unauthorized privilege escalation, complete loss of system integrity, or denial of service, which would significantly impact the availability and security of the affected hardware platforms.
Remediation
Immediate Action: Review the January 2026 Qualcomm security bulletin and apply the vendor-provided firmware or software updates to all affected devices as soon as they become available.
Proactive Monitoring: Monitor system logs for unusual crash patterns or unexpected process termination that may indicate attempted exploitation of memory-related functions.
Compensating Controls: Restrict local access to the affected devices to trusted users only, as the vulnerability requires local access to the system to be successfully exploited.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the nature of the memory corruption, administrators should prioritize updating their Qualcomm-based infrastructure. Verify your hardware inventory against the list of affected platforms and ensure that the latest security patches from Qualcomm are deployed immediately upon release to mitigate the risk of local privilege escalation.