Memory Corruption Vulnerability in Qualcomm Products
CVE-2025-27060

8.8HIGH

Key Information:

Vendor

Qualcomm

Vendor
CVE Published:
9 October 2025

What is CVE-2025-27060?

This vulnerability manifests as memory corruption when a System Control Management (SCM) call is executed with malformed inputs. This can lead to unexpected behavior, system instability, or potential exploitation, highlighting the importance of ensuring secure input validation across Qualcomm embedded systems.

Affected Version(s)

Snapdragon Snapdragon Wired Infrastructure and Networking Immersive Home 214 Platform

Snapdragon Snapdragon Wired Infrastructure and Networking Immersive Home 216 Platform

Snapdragon Snapdragon Wired Infrastructure and Networking Immersive Home 316 Platform

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-27060 : Memory Corruption Vulnerability in Qualcomm Products