Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-27070

CVE-2025-27070: Qualcomm Qcs615 Buffer Overflow Vulnerability

CVE-2025-27070 is a buffer overflow flaw in Qualcomm Qcs615 Firmware that causes memory corruption during encryption and decryption operations. This article covers technical details, affected versions, and mitigation.

Updated:

CVE-2025-27070 Overview

CVE-2025-27070 is a memory corruption vulnerability affecting a broad range of Qualcomm chipsets and firmware. The flaw occurs while performing encryption and decryption commands, and is classified under [CWE-787: Out-of-bounds Write]. Exploitation requires local access with low privileges and no user interaction. Successful exploitation compromises confidentiality, integrity, and availability of the affected device.

The vulnerability was disclosed in the Qualcomm Security Bulletin November 2025 and impacts hundreds of Snapdragon mobile, automotive, compute, IoT, and modem-RF platforms.

Critical Impact

A local, low-privileged attacker can trigger an out-of-bounds write during cryptographic command handling, leading to memory corruption, code execution, or device compromise on affected Qualcomm chipsets.

Affected Products

  • Qualcomm Snapdragon mobile platforms including Snapdragon 8 Gen 1/2/3, 8+ Gen 2, 888, 870, 865, 765, 695, 685, 680, 662, 480, 460, and 4 Gen 1
  • Qualcomm automotive and compute platforms including SA8155P, SA8255P, SA8295P, SA8775P, SC8380XP, and Snapdragon 8cx Gen 3 compute platforms
  • Qualcomm connectivity, IoT, and modem-RF products including FastConnect 6200/6700/6800/6900/7800, QCA6xxx series, QCN6xxx/9xxx series, WCN3xxx/6xxx/7xxx series, and Snapdragon X32/X35/X55/X62/X65/X72/X75 5G Modem-RF Systems

Discovery Timeline

  • 2025-11-04 - CVE-2025-27070 published to NVD
  • 2025-11 - Qualcomm publishes November 2025 Security Bulletin with patch guidance
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-27070

Vulnerability Analysis

The vulnerability resides in the cryptographic command handling path of Qualcomm firmware. When the affected code processes encryption and decryption commands, an out-of-bounds write condition occurs, corrupting adjacent memory. Because the flaw is triggered by a local low-privileged caller, an attacker with code execution on the device can craft cryptographic requests that overwrite memory outside the intended buffer.

The scope remains unchanged, meaning the corruption occurs within the security authority handling the request. Depending on the affected component, that authority may be a trusted execution environment (TEE), a modem processor, or a device driver interfacing with Qualcomm hardware crypto engines. Corrupting memory in these authorities threatens key material confidentiality, kernel-level integrity, and device availability.

Root Cause

The root cause is an out-of-bounds write [CWE-787] during the parsing or processing of parameters supplied to encryption and decryption command handlers. Insufficient bounds validation on attacker-controlled inputs allows the handler to write past the end of an allocated buffer. Qualcomm has not publicly released detailed function-level information for this issue.

Attack Vector

An attacker requires local access to the device with low privileges. Typical exploitation paths include a malicious application on an Android device, a compromised process on an automotive or compute platform, or a local user on an IoT device. The attacker issues crafted encryption or decryption commands to the vulnerable interface. The out-of-bounds write can then be shaped to overwrite security-relevant structures such as function pointers, cryptographic keys, or command buffers, enabling privilege escalation or code execution in the affected component.

No public proof-of-concept exploit or in-the-wild exploitation has been reported. See the Qualcomm Security Bulletin November 2025 for vendor technical details.

Detection Methods for CVE-2025-27070

Indicators of Compromise

  • Unexpected crashes, panics, or reboots in components handling cryptographic operations, such as qseecomd, TEE services, or modem subsystems
  • Kernel or subsystem logs referencing memory faults, SIGSEGV, or aborts during encrypt/decrypt syscalls issued by unprivileged processes
  • Applications with no legitimate cryptographic role invoking QSEE or crypto ioctl interfaces at high frequency

Detection Strategies

  • Inventory devices against the affected Qualcomm chipset list and confirm firmware build against the November 2025 Qualcomm Security Bulletin baseline
  • Monitor mobile device management (MDM) telemetry for devices missing the November 2025 or later Android/OEM security patch level
  • Correlate application behavior with access to cryptographic IPC endpoints and flag unsigned or newly installed apps that touch these interfaces

Monitoring Recommendations

  • Enable crash reporting and kernel log forwarding from managed endpoints to a central log store for anomaly review
  • Baseline normal use of Qualcomm crypto services per device role and alert on deviations, especially repeated aborts
  • Track patch compliance for firmware and OEM images shipping the fix distributed by Qualcomm in the November 2025 bulletin

How to Mitigate CVE-2025-27070

Immediate Actions Required

  • Identify all devices using affected Qualcomm chipsets across mobile, automotive, compute, and IoT fleets
  • Apply the OEM firmware update that incorporates the Qualcomm November 2025 patch as soon as it is available from the device manufacturer
  • Restrict installation of untrusted applications on affected mobile and IoT devices until patches are deployed

Patch Information

Qualcomm addressed CVE-2025-27070 in the November 2025 Qualcomm Security Bulletin. The fix is delivered through Qualcomm firmware updates that OEMs integrate into their device software releases. Contact device manufacturers for availability of the corresponding firmware or Android security patch level for each affected model.

Workarounds

  • Limit local access to affected devices by enforcing strong lockscreen, MDM, and app installation policies
  • Block or restrict sideloading of applications on Android devices and monitor for privilege abuse until patches are applied
  • For automotive and embedded deployments, isolate affected control units on segmented networks and disable unused local interfaces

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.