CVE-2025-47405

7.8

Qualcomm · Snapdragon

Memory corruption vulnerability in Qualcomm Snapdragon camera sensor input/output control codes allows local privilege escalation.

Executive summary

An untrusted pointer dereference vulnerability in multiple Qualcomm Snapdragon products allows a low-privileged local attacker to achieve complete system compromise through memory corruption.

Vulnerability

This vulnerability is an untrusted pointer dereference (CWE-822) occurring during the processing of camera sensor input/output control codes with invalid output buffers, requiring low local privileges and no user interaction for successful exploitation.

Business impact

A successful exploit can lead to complete confidentiality, integrity, and availability loss on the affected device, potentially allowing an attacker to execute arbitrary code with elevated privileges. This severity is justified by the CVSS score of 7.8, which highlights the significant risk of local system compromise despite requiring prior local access.

Remediation

Immediate Action: Apply the vendor security updates provided in the Qualcomm May 2026 security bulletin as soon as they are available.

Proactive Monitoring: Monitor system logs for unusual kernel crashes or anomalous behavior related to camera sensor input/output control operations.

Compensating Controls: Restrict local user access and enforce strict least privilege principles to minimize the risk of unauthorized local execution.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing affected Qualcomm Snapdragon hardware must prioritize reviewing vendor advisories and applying the necessary firmware or software patches immediately. Securing local environments against unauthorized access remains a critical step while patches are deployed to prevent local escalation attempts.

More Qualcomm CVEs

Sources