CVE-2025-47407

7.8

Qualcomm · Snapdragon and FastConnect

A kernel level memory corruption flaw in Qualcomm digital signal processors allows local authenticated attackers to achieve high impact system compromise.

Executive summary

A time-of-check time-of-use race condition vulnerability in Qualcomm digital signal processors allows local attackers to execute arbitrary code and compromise kernel integrity.

Vulnerability

This is a time-of-check time-of-use race condition vulnerability mapped to CWE-367, triggered during process creation on the digital signal processor due to a kernel level memory allocation failure, requiring low local privileges and no user interaction.

Business impact

A successful exploit can result in complete system compromise, leading to total confidentiality, integrity, and availability losses. The CVSS score of 7.8 reflects the high severity of potential local privilege escalation and subsequent host takeover.

Remediation

Immediate Action: Apply the official security updates provided in the Qualcomm May 2026 security bulletin as soon as they become available for your specific hardware platform.

Proactive Monitoring: Monitor system logs for unusual kernel panics, unexpected reboots, or unauthorized process creation activities targeting digital signal processor components.

Compensating Controls: Restrict local user access and enforce strict privilege management policies to prevent unauthorized accounts from executing code on vulnerable endpoints.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Organizations utilizing affected Qualcomm Snapdragon and FastConnect hardware must review the vendor advisory and apply necessary firmware updates promptly. Prioritize endpoints running sensitive workloads to mitigate the risk of local kernel compromise.

More Qualcomm CVEs

Sources