Buffer over-read in Qualcomm products - CVE-2025-27033
Published: September 1, 2025
Vulnerability identifier: #VU114655
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-27033
CWE-ID: CWE-126
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to read and manipulate data.
The vulnerability exists due to improper input validation in Video. A local application can read and manipulate data.
Affected software
SM8635P
WCN7881
WCN7861
WCN7860
WCN7880
WCN7850
WCN6755
WCN6650
QCA6698AQ
WCN7851
QCN9274
WCN6856
WCN6750
SXR2330P
SM8750P
SM8750
QCM5430
SM8635
SM7675P
SM7675
SM8650Q
SM8650P
SM8650
SM7635
SM6650
QCS9100
QCS615
QCS8550
QCM8550
QCS6490
QCS5430
QCM6490
WCN7881
WCN7861
WCN7860
WCN7880
WCN7850
WCN6755
WCN6650
QCA6698AQ
WCN7851
QCN9274
WCN6856
WCN6750
SXR2330P
SM8750P
SM8750
QCM5430
SM8635
SM7675P
SM7675
SM8650Q
SM8650P
SM8650
SM7635
SM6650
QCS9100
QCS615
QCS8550
QCM8550
QCS6490
QCS5430
QCM6490
How to mitigate CVE-2025-27033
Install security update from vendor's website.