CVE-2025-47408

7.8

Qualcomm · Snapdragon and related FastConnect/IQX chipsets

An untrusted pointer dereference vulnerability in Qualcomm products leads to memory corruption when processing invalid IOCTL buffers.

Executive summary

An untrusted pointer dereference vulnerability in multiple Qualcomm Snapdragon and FastConnect chipsets allows local authenticated attackers to achieve total system compromise through memory corruption.

Vulnerability

This flaw is classified as an untrusted pointer dereference (CWE-822), triggered when an interacting driver sends an IOCTL call with invalid input or output buffers, requiring low local privileges (PR:L) with no user interaction (UI:N).

Business impact

The CVSS score of 7.8 reflects a high severity risk that can lead to total loss of confidentiality, integrity, and availability. Successful exploitation allows an attacker with local access to corrupt system memory, potentially escalating privileges, executing arbitrary code, or causing persistent denial of service across affected hardware components.

Remediation

Immediate Action: Apply the vendor security updates provided in the May 2026 Qualcomm security bulletin as soon as possible.

Proactive Monitoring: Monitor system logs for unusual kernel driver behaviors, unexpected reboots, or segmentation faults related to driver communication.

Compensating Controls: Restrict local system access to authorized personnel only and enforce principle of least privilege to minimize the risk of malicious local code execution.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Given the high CVSS score and the potential for total system compromise, administrators should prioritize updating affected Qualcomm drivers and firmware. Coordinate with device manufacturers to deploy available patches immediately to mitigate local privilege escalation risks.

More Qualcomm CVEs

Sources