PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-47332 Qualcomm, Inc. CVE debrief

CVE-2025-47332 is a memory corruption vulnerability in Qualcomm FastConnect and Snapdragon devices. The vulnerability occurs when processing a config call from userspace, potentially leading to device compromise. Defenders of Qualcomm FastConnect and Snapdragon devices should assess exposure and apply patches. The CVE record was published on 2026-01-07T12:17:02.680Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability requires patching to prevent memory corruption and defenders must assess exposure, apply patches, and verify system integrity.

Vendor
Qualcomm, Inc.
Product
Snapdragon
CVSS
MEDIUM 6.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-07
Original CVE updated
2026-09-30
Advisory published
2026-01-07
Advisory updated
2026-09-30

Who should care

Defenders of Qualcomm FastConnect and Snapdragon devices, security teams, and vulnerability management teams should assess exposure and apply patches. Additionally, operators and platform administrators may need to review and verify system integrity. The vulnerability requires attention from teams responsible for maintaining device security and integrity.

Why it matters

CVE-2025-47332 requires patching for Qualcomm FastConnect and Snapdragon devices to prevent memory corruption. Defenders must assess exposure, apply patches, and verify system integrity.

  • Memory corruption attempts may lead to device compromise
  • Patching is required to prevent memory corruption
  • Verification of patch application is necessary
  • Exposure assessment is required for Qualcomm devices

Technical summary

CVE-2025-47332 is a memory corruption vulnerability in Qualcomm FastConnect and Snapdragon devices. A config call from userspace can lead to memory corruption with a CVSS score of 6.7 (Medium). The vulnerability affects Qualcomm FastConnect and Snapdragon devices, and defenders should prioritize patching to prevent potential device compromise. The technical details are based on publicly available information and may not be exhaustive.

Defensive priority

Qualcomm FastConnect and Snapdragon devices require memory corruption patching

Recommended defensive actions

  • Inventory and assess exposure of Qualcomm FastConnect and Snapdragon devices
  • Apply patch from Qualcomm security bulletin
  • Monitor for memory corruption attempts
  • Verify patch application and system integrity

Evidence notes

Official CVE Program and NVD records provide memory corruption details. Qualcomm provides patch guidance in security bulletin. The evidence is limited to publicly available information and may not reflect the full scope of affected systems or potential impacts. Defenders should verify patch application and system integrity.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-47332 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-47332

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-47332 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-47332

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2026-bulletin.html

    [email protected] - Patch, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.