Improper Access Control for Register Interface in Qualcomm products - CVE-2025-47385

 

Improper Access Control for Register Interface in Qualcomm products - CVE-2025-47385

Published: March 2, 2026


Vulnerability identifier: #VU123407
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-47385
CWE-ID: CWE-1262
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in SCE-Mink. A local application can execute arbitrary code.


Affected software

Snapdragon 6 Gen 3 Mobile Platform
SXR2330P
SW5100P
SW5100
SRV1M
SRV1H
Snapdragon W5+ Gen 1 Wearable Platform
Snapdragon AR1+ Gen 1 Platform
Snapdragon 8 Elite
Snapdragon 7s Gen 3 Mobile Platform
Snapdragon 695 5G Mobile Platform
Snapdragon 6 Gen 4 Mobile Platform
SXR2350P
Snapdragon 6 Gen 1 Mobile Platform
Snapdragon 480+ 5G Mobile Platform
Snapdragon 480 5G Mobile Platform
Snapdragon 4 Gen 2 Mobile Platform
Snapdragon 4 Gen 1 Mobile Platform
SM8750P
SM7435
SAR2230P
SAR1250P
SAR1165P
WCN7860
WSA8845H
WSA8845
WSA8840
WSA8835
WSA8830
WSA8815
WSA8810
WCN7881
WCN7880
WCN7861
SA8770P
WCN6755
WCN6450
WCN3988
WCN3950
WCD9395
WCD9385
WCD9380
WCD9378
WCD9375
WCD9370
QAM8255P
QCA6698AQ
QCA6696
QCA6688AQ
QCA6595AU
QCA6595
QCA6574A
QCA6574
QAMSRV1M
QAMSRV1H
QAM8295P
QCA6797AQ
Pandeiro
Palawan25
Orne
Netrani
Milos
LeMansAU
LeMans_AU_LGIT
G2 Gen 1
FastConnect 7800
FastConnect 6900
FastConnect 6700
QXM1093
SA8295P
SA8255P
SA8195P
SA8155P
SA7775P
SA7255P
QXM1096
QXM1095
QXM1094
FastConnect 6200
QXM1086
QXM1083
QPA1086BD
QPA1083BD
QMP1000
QLN1086BD
QLN1083BD
QCA9367
QCA8695AU
SA9000P
WSA8832
QCA6574AU
SA8620P
SA6155P
QCA9377
Google Android

How to mitigate CVE-2025-47385

Install security update from vendor's website.

Google Android - addressed in versions 14 2026-03-05, 15 2026-03-05, 16-qpr2 2026-03-05, 16 2026-03-05

External References

Related Security Bulletins