8.8
HIGH CVSS 3.1
CVE-2025-27059
Use of Out-of-range Pointer Offset in TZ Firmware
Description

Memory corruption while performing SCM call.

INFO

Published Date :

Oct. 9, 2025, 4:16 a.m.

Last Modified :

Oct. 21, 2025, 4:41 p.m.

Remotely Exploit :

No
Affected Products

The following products are affected by CVE-2025-27059 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Qualcomm immersive_home_214_platform_firmware
2 Qualcomm immersive_home_216_platform_firmware
3 Qualcomm immersive_home_316_platform_firmware
4 Qualcomm immersive_home_318_platform_firmware
5 Qualcomm ipq5010_firmware
6 Qualcomm ipq5028_firmware
7 Qualcomm qcn6023_firmware
8 Qualcomm qcn6024_firmware
9 Qualcomm qcn6100_firmware
10 Qualcomm qcn6102_firmware
11 Qualcomm qcn6112_firmware
12 Qualcomm qcn6122_firmware
13 Qualcomm qcn6132_firmware
14 Qualcomm qcn9000_firmware
15 Qualcomm qcn9001_firmware
16 Qualcomm qcn9002_firmware
17 Qualcomm qcn9003_firmware
18 Qualcomm qcn9012_firmware
19 Qualcomm qcn9022_firmware
20 Qualcomm qcn9024_firmware
21 Qualcomm qcn9070_firmware
22 Qualcomm qcn9072_firmware
23 Qualcomm qcn9074_firmware
24 Qualcomm qcn9100_firmware
25 Qualcomm qcn9274_firmware
26 Qualcomm qcn9000
27 Qualcomm qcn9074
28 Qualcomm ipq5010
29 Qualcomm qcn6023
30 Qualcomm qcn6024
31 Qualcomm qcn9012
32 Qualcomm qcn9022
33 Qualcomm qcn9024
34 Qualcomm qcn9070
35 Qualcomm qcn9072
36 Qualcomm qcn9100
37 Qualcomm immersive_home_214_platform
38 Qualcomm immersive_home_216_platform
39 Qualcomm immersive_home_316_platform
40 Qualcomm immersive_home_318_platform
41 Qualcomm qcn9274
42 Qualcomm ipq5028
43 Qualcomm qcn6112
44 Qualcomm qcn6122
45 Qualcomm qcn6132
46 Qualcomm qcn6100
47 Qualcomm qcn6102
48 Qualcomm qcn9001
49 Qualcomm qcn9002
50 Qualcomm qcn9003
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH 2cfc7d3e-20d3-47ac-8db7-1b7285aff15f
CVSS 3.1 HIGH [email protected]
Solution
Address memory corruption in SCM calls through code review and patching.
  • Review SCM call implementation for memory safety.
  • Apply patches to fix memory corruption issues.
  • Test thoroughly after applying fixes.
  • Update the affected software.
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2025-27059.

URL Resource
https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2025-bulletin.html Vendor Advisory
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2025-27059 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2025-27059 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2025-27059 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2025-27059 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Oct. 21, 2025

    Action Type Old Value New Value
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:immersive_home_214_platform_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:immersive_home_214_platform:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:immersive_home_216_platform_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:immersive_home_216_platform:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:immersive_home_316_platform_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:immersive_home_316_platform:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:immersive_home_318_platform_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:immersive_home_318_platform:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq5010_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq5010:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq5028_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq5028:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6023_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6023:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6024_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6024:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6100_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6100:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6102_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6102:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6112_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6112:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6122_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6122:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6132_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6132:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9000_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9000:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9001_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9001:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9002_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9002:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9003_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9003:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9012_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9012:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9022_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9022:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9024_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9024:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9070_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9070:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9072_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9072:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9074_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9074:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9100_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9100:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9274_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9274:-:*:*:*:*:*:*:*
    Added Reference Type Qualcomm, Inc.: https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2025-bulletin.html Types: Vendor Advisory
  • New CVE Received by [email protected]

    Oct. 09, 2025

    Action Type Old Value New Value
    Added Description Memory corruption while performing SCM call.
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    Added CWE CWE-823
    Added Reference https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2025-bulletin.html
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
Vulnerability Scoring Details
Base CVSS Score: 8.8
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact