Exposure of Sensitive System Information to an Unauthorized Control Sphere in Qualcomm products - CVE-2025-47378

 

Exposure of Sensitive System Information to an Unauthorized Control Sphere in Qualcomm products - CVE-2025-47378

Published: March 2, 2026


Vulnerability identifier: #VU123405
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-47378
CWE-ID: CWE-497
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to read and manipulate data.

The vulnerability exists due to improper input validation in HLOS. A local application can read and manipulate data.


Affected software

Snapdragon XR2+ Gen 1 Platform
WCN3950
WCD9395
WCD9385
WCD9380
WCD9378C
SXR2250P
SXR2230P
SRV1M
SRV1H
WCN7860
Snapdragon XR2 5G Platform
Snapdragon X55 5G Modem-RF System
Snapdragon AR1+ Gen 1 Platform
Snapdragon AR1 Gen 1 Platform
Snapdragon 870 5G Mobile Platform
Snapdragon 865+ 5G Mobile Platform
Snapdragon 865 5G Mobile Platform
Snapdragon 8 Elite Gen 5
WSA8845H
XG101039
XG101032
XG101002
X2000094
X2000092
X2000090
X2000086
X2000077
SD865 5G
WSA8845
WSA8840
WSA8835
WSA8830
WSA8815
WSA8810
WCN7861
QAMSRV1H
QLN1086BD
QLN1083BD
QCA6797AQ
QCA6698AQ
QCA6696
QCA6595AU
QCA6595
QCA6391
QAMSRV1M
QPA1083BD
QAM8255P
Pandeiro
LeMansAU
LeMans_AU_LGIT
FastConnect 7800
FastConnect 6900
FastConnect 6800
FastConnect 6700
SA7775P
SAR2230P
SAR2130P
SAR1250P
SAR1165P
SA8770P
SA8255P
Cologne
SA7255P
QXM1096
QXM1095
QXM1094
QXM1093
QXM1086
QXM1083
QPA1086BD
WSA8832
SA9000P
SA8620P
Google Android

How to mitigate CVE-2025-47378

Install security update from vendor's website.

Google Android - addressed in versions 14 2026-03-05, 15 2026-03-05, 16-qpr2 2026-03-05, 16 2026-03-05

External References

Related Security Bulletins