PatchSiren cyber security CVE debrief
CVE-2025-47335 Qualcomm, Inc. CVE debrief
CVE-2025-47335 is a memory corruption vulnerability in Qualcomm hardware while parsing clock configuration data. Defenders should assess exposure for systems using affected Qualcomm hardware and prioritize patching. The vulnerability has a CVSS score of 6.7 and is considered medium severity. Qualcomm has provided a security bulletin with patch information. Affected systems require immediate attention to prevent potential exploitation. The vulnerability's impact can be mitigated by applying patches from Qualcomm for affected devices and monitoring for unusual activity on affected systems.
- Vendor
- Qualcomm, Inc.
- Product
- Snapdragon
- CVSS
- MEDIUM 6.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-07
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-07
- Advisory updated
- 2026-09-30
Who should care
Defenders managing systems with affected Qualcomm hardware should assess exposure and apply patches. Prioritization is crucial for systems with high-risk exposure. Inventory of affected Qualcomm hardware is necessary for efficient patch management. Security teams should monitor for unusual activity on affected systems and verify patch deployment.
Why it matters
CVE-2025-47335 is a medium-severity memory corruption vulnerability in Qualcomm hardware. Defenders should prioritize patching affected devices and monitoring for unusual activity.
- Verify patch deployment for affected Qualcomm hardware
- Monitor for unusual activity on affected systems
- Inventory affected Qualcomm hardware for prioritization
Technical summary
The vulnerability is caused by memory corruption while parsing clock configuration data for a specific hardware type. It has a CVSS score of 6.7 and is considered medium severity. The vulnerability affects Qualcomm hardware, and defenders should focus on patching affected devices. Technical details are limited to the information provided in the CVE record and NVD detail page.
Defensive priority
Apply patches from Qualcomm for affected devices.
Recommended defensive actions
- Apply patches from Qualcomm for affected devices
- Inventory affected Qualcomm hardware
- Monitor for unusual activity on affected systems
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability. Qualcomm's security bulletin offers patch details. Evidence is limited to public sources, and defenders should verify patch deployment for affected Qualcomm hardware. The CVE record was published on 2026-01-07T12:17:03.180Z and has not been modified since then. The NVD entry is currently Analyzed. No additional information is available beyond these sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-47335 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-47335
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-47335 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-47335
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2026-bulletin.html
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.