PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-47369 Qualcomm, Inc. CVE debrief

Qualcomm released a security bulletin addressing CVE-2025-47369, an information disclosure vulnerability. The CVE record was published on 2026-01-07T12:17:04.783Z and last modified on 2026-09-30T23:10:00.237Z. The NVD entry is currently Analyzed. This vulnerability affects various Qualcomm products, including AR8035, CSRA6620, CSRA6640, FastConnect 6200, FastConnect 6700, Snapdragon W5+ Gen 1 Wearable Platform, Snapdragon X12 LTE Modem, Snapdragon X55 5G Modem-RF System, Snapdragon X65 5G Modem-RF System, Snapdragon XR2 5G Platform, and Snapdragon XR2+ Gen 1 Platform. Defenders should assess exposure and prioritize patching for these affected devices.

Vendor
Qualcomm, Inc.
Product
Snapdragon
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-07
Original CVE updated
2026-09-30
Advisory published
2026-01-07
Advisory updated
2026-09-30

Who should care

Defenders responsible for Qualcomm-based systems, including those using AR8035, CSRA6620, CSRA6640, FastConnect 6200, FastConnect 6700, Snapdragon W5+ Gen 1 Wearable Platform, Snapdragon X12 LTE Modem, Snapdragon X55 5G Modem-RF System, Snapdragon X65 5G Modem-RF System, Snapdragon XR2 5G Platform, and Snapdragon XR2+ Gen 1 Platform, should assess exposure and prioritize patching.

Why it matters

CVE-2025-47369 is a medium-severity information disclosure vulnerability in various Qualcomm products. Defenders should prioritize verifying exposure and assessing compensating controls for affected devices.

  • Verify exposure of Qualcomm products in inventory
  • Assess compensating controls for affected devices
  • Monitor for potential information disclosure
  • Apply patches from Qualcomm as available

Technical summary

CVE-2025-47369 is an information disclosure vulnerability in Qualcomm products. A weak hashed value returned to userland code in response to an IOCTL call to obtain a session ID could result in information disclosure. The vulnerability is caused by the improper handling of sensitive information in the IOCTL call, which could allow an attacker to access sensitive data. Defenders should prioritize verifying exposure and assessing compensating controls for Qualcomm products using the affected components.

Defensive priority

Defenders should prioritize verifying exposure and assessing compensating controls for Qualcomm products using the AR8035, CSRA6620, CSRA6640, FastConnect 6200, FastConnect 6700, Snapdragon W5+ Gen 1 Wearable Platform, Snapdragon X12 LTE Modem, Snapdragon X55 5G Modem-RF System, Snapdragon X65 5G Modem-RF System, Snapdragon XR2 5G Platform, and Snapdragon XR2+ Gen 1 Platform.

Recommended defensive actions

  • Verify exposure of Qualcomm products in inventory
  • Assess compensating controls for affected devices
  • Monitor for potential information disclosure
  • Apply patches from Qualcomm as available

Evidence notes

The CVE description notes that a weak hashed value returned to userland code in response to an IOCTL call to obtain a session ID could result in information disclosure. However, specific details about exploitation, impact, or remediation are limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-47369 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-47369

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-47369 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-47369

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2026-bulletin.html

    [email protected] - Patch, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.