Information Disclosure Vulnerability in Qualcomm's Diagnostic Command Processing
CVE-2025-27064

6.1MEDIUM

Key Information:

Vendor

Qualcomm

Vendor
CVE Published:
4 November 2025

What is CVE-2025-27064?

A vulnerability exists in Qualcomm's diagnostic command processing, where sensitive data may be disclosed to unauthorized clients due to improper handling of commands registered through diagHal. This can lead to potential exposure of confidential information, which could be exploited by malicious users to gain insights into system configurations or operations.

Affected Version(s)

Snapdragon Snapdragon Auto FastConnect 6900

Snapdragon Snapdragon Auto FastConnect 7800

Snapdragon Snapdragon Auto Immersive Home 3210 Platform

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-27064 : Information Disclosure Vulnerability in Qualcomm's Diagnostic Command Processing