PatchSiren cyber security CVE debrief
CVE-2025-47406 Qualcomm, Inc. CVE debrief
CVE-2025-47406 is a medium-severity vulnerability affecting Qualcomm's Snapdragon and other products, allowing for information disclosure due to improper buffer size verification in IOCTL handler callbacks. This vulnerability has a CVSS score of 6.1 and is classified as MEDIUM. The vulnerability affects various Qualcomm Snapdragon and related products. Defenders and security teams responsible for Qualcomm Snapdragon and related products should assess exposure and prioritize patching based on their specific deployment contexts. The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and affected products.
- Vendor
- Qualcomm, Inc.
- Product
- Snapdragon
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-04
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-05-04
- Advisory updated
- 2026-09-30
Who should care
Defenders and security teams responsible for Qualcomm Snapdragon and related products should assess exposure and prioritize patching based on their specific deployment contexts.
Why it matters
CVE-2025-47406 is a medium-severity vulnerability affecting Qualcomm Snapdragon products, allowing for information disclosure. Defenders should prioritize verifying and applying patches, assessing exposure based on specific deployment contexts.
- Information disclosure may occur due to improper buffer size verification
- Defenders should verify and apply patches from Qualcomm
- Exposure assessment is necessary for specific deployment contexts
- Remediation priority is medium due to the CVSS score of 6.1
Technical summary
The vulnerability, CVE-2025-47406, is caused by improper buffer size verification in IOCTL handler callbacks, leading to information disclosure. It affects various Qualcomm Snapdragon and related products, including but not limited to Snapdragon 888 5G Mobile Platform, Snapdragon 888+ 5G Mobile Platform, and Snapdragon 8 Gen 1 5G Mobile Platform. The vulnerability has a CVSS score of 6.1, indicating a medium severity level. Defenders should prioritize verifying and applying patches from Qualcomm, assessing exposure based on their specific deployment contexts, and
Defensive priority
Qualcomm Snapdragon and related product users should prioritize verifying and applying patches from the vendor, assessing exposure based on their specific deployment contexts.
Recommended defensive actions
- Verify and apply patches from Qualcomm for affected Snapdragon and related products
- Assess exposure based on specific deployment contexts
- Review and update inventory of affected products
- Monitor for potential information disclosure
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and affected products. A vendor advisory is available from Qualcomm.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-47406 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-47406
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-47406 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-47406
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2026-bulletin.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.