PatchSiren cyber security CVE debrief
CVE-2025-47369 Qualcomm, Inc. CVE debrief
Qualcomm released a security bulletin addressing CVE-2025-47369, an information disclosure vulnerability. The CVE record was published on 2026-01-07T12:17:04.783Z and last modified on 2026-09-30T23:10:00.237Z. The NVD entry is currently Analyzed. This vulnerability affects various Qualcomm products, including AR8035, CSRA6620, CSRA6640, FastConnect 6200, FastConnect 6700, Snapdragon W5+ Gen 1 Wearable Platform, Snapdragon X12 LTE Modem, Snapdragon X55 5G Modem-RF System, Snapdragon X65 5G Modem-RF System, Snapdragon XR2 5G Platform, and Snapdragon XR2+ Gen 1 Platform. Defenders should assess exposure and prioritize patching for these affected devices.
- Vendor
- Qualcomm, Inc.
- Product
- Snapdragon
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-07
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-07
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for Qualcomm-based systems, including those using AR8035, CSRA6620, CSRA6640, FastConnect 6200, FastConnect 6700, Snapdragon W5+ Gen 1 Wearable Platform, Snapdragon X12 LTE Modem, Snapdragon X55 5G Modem-RF System, Snapdragon X65 5G Modem-RF System, Snapdragon XR2 5G Platform, and Snapdragon XR2+ Gen 1 Platform, should assess exposure and prioritize patching.
Why it matters
CVE-2025-47369 is a medium-severity information disclosure vulnerability in various Qualcomm products. Defenders should prioritize verifying exposure and assessing compensating controls for affected devices.
- Verify exposure of Qualcomm products in inventory
- Assess compensating controls for affected devices
- Monitor for potential information disclosure
- Apply patches from Qualcomm as available
Technical summary
CVE-2025-47369 is an information disclosure vulnerability in Qualcomm products. A weak hashed value returned to userland code in response to an IOCTL call to obtain a session ID could result in information disclosure. The vulnerability is caused by the improper handling of sensitive information in the IOCTL call, which could allow an attacker to access sensitive data. Defenders should prioritize verifying exposure and assessing compensating controls for Qualcomm products using the affected components.
Defensive priority
Defenders should prioritize verifying exposure and assessing compensating controls for Qualcomm products using the AR8035, CSRA6620, CSRA6640, FastConnect 6200, FastConnect 6700, Snapdragon W5+ Gen 1 Wearable Platform, Snapdragon X12 LTE Modem, Snapdragon X55 5G Modem-RF System, Snapdragon X65 5G Modem-RF System, Snapdragon XR2 5G Platform, and Snapdragon XR2+ Gen 1 Platform.
Recommended defensive actions
- Verify exposure of Qualcomm products in inventory
- Assess compensating controls for affected devices
- Monitor for potential information disclosure
- Apply patches from Qualcomm as available
Evidence notes
The CVE description notes that a weak hashed value returned to userland code in response to an IOCTL call to obtain a session ID could result in information disclosure. However, specific details about exploitation, impact, or remediation are limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-47369 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-47369
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-47369 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-47369
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2026-bulletin.html
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.