PatchSiren cyber security CVE debrief
CVE-2025-47348 Qualcomm, Inc. CVE debrief
CVE-2025-47348 is a high-severity memory corruption vulnerability in Qualcomm trusted applications. The vulnerability has a CVSS score of 7.8 and can lead to confidentiality, integrity, and availability impacts. Developers and deployers should assess exposure and prioritize verification of affected versions and compensating controls. The CVE record was published on 2026-01-07T12:17:04.457Z and has not been modified since then. The NVD entry is currently Analyzed. Qualcomm trusted application developers, deployers, and system administrators should verify system configurations and compensating controls.
- Vendor
- Qualcomm, Inc.
- Product
- Snapdragon
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-07
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-07
- Advisory updated
- 2026-09-30
Who should care
Qualcomm trusted application developers, deployers, and system administrators should assess exposure and prioritize verification of affected versions and compensating controls. They should also verify system configurations and compensating controls. Additionally, vulnerability management and security teams should review the CVE and NVD details for vulnerability specifics and check Qualcomm advisory for patch信息.
Why it matters
CVE-2025-47348 is a high-severity vulnerability in Qualcomm trusted applications that requires prompt attention from developers and deployers to assess exposure and prioritize mitigation.
- Verification of affected versions and patch deployment
- Assessment of trusted application configurations and compensating controls
- Monitoring for suspicious activity related to identity credential operations
- Evaluation of system resilience against potential memory corruption
Technical summary
CVE-2025-47348 is a high-severity memory corruption vulnerability in Qualcomm trusted application. The vulnerability has a CVSS score of 7.8 and can lead to confidentiality, integrity, and availability impacts. The vulnerability is related to memory corruption while processing identity credential operations in the trusted application. Developers and deployers should assess exposure and prioritize verification of affected versions and compensating controls.
Defensive priority
Qualcomm trusted application developers and deployers should assess exposure and prioritize verification of affected versions and compensating controls.
Recommended defensive actions
- Review CVE and NVD details for vulnerability specifics
- Check Qualcomm advisory for patch information
- Assess exposure of trusted applications using affected Qualcomm components
- Verify system configurations and compensating controls
Evidence notes
The CVE Program record and NVD vulnerability detail provide official metadata and assessment. A vendor advisory from Qualcomm is available. The evidence is limited to the supplied source corpus and CVE Program record. Defenders should verify the affected scope and severity with Qualcomm and assess exposure of trusted applications using affected Qualcomm components.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-47348 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-47348
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-47348 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-47348
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2026-bulletin.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.