Information Disclosure in Hypervisor Log Processing for Qualcomm Products
CVE-2025-27040

6.5MEDIUM

Key Information:

Vendor

Qualcomm

Vendor
CVE Published:
9 October 2025

What is CVE-2025-27040?

An information disclosure vulnerability exists in the way Qualcomm hypervisor processes log data. This flaw could allow unauthorized access to sensitive information within the logs, potentially exposing critical data that could be leveraged for further attacks. Mitigation strategies are essential to safeguard against risks associated with this vulnerability, ensuring the integrity of data processed by the hypervisor.

Affected Version(s)

Snapdragon Snapdragon Wired Infrastructure and Networking CSR8811

Snapdragon Snapdragon Wired Infrastructure and Networking Immersive Home 214 Platform

Snapdragon Snapdragon Wired Infrastructure and Networking Immersive Home 216 Platform

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-27040 : Information Disclosure in Hypervisor Log Processing for Qualcomm Products