Memory Corruption Issue in Qualcomm Virtual Machine Management Software
CVE-2025-21460

7.8HIGH

Key Information:

Vendor
Qualcomm
Vendor
CVE Published:
6 May 2025

Summary

A vulnerability in Qualcomm's Virtual Machine Management Software allows for memory corruption when processing messages from guest virtual machines. An attacker controlling the guest VM may manipulate the buffer, potentially altering the memory content continuously, which could lead to instability or unauthorized access in the management layer.

Affected Version(s)

Snapdragon Snapdragon Auto QAM8255P

Snapdragon Snapdragon Auto QAM8295P

Snapdragon Snapdragon Auto QAM8620P

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.