Qualcomm Snapdragon Chipsets RTCP Packet Processing Vulnerability During VoLTE/VoWiFi IMS Calls

Vulnerability

A buffer over-read vulnerability has been identified in various chipsets of Qualcomm Snapdragon, FastConnect, and other platforms. This vulnerability occurs when an invalid RTCP packet is received during a Voice over LTE (VoLTE) or Voice over WiFi (VoWiFi) IP Multimedia Subsystem (IMS) call, leading to information disclosure.

Impact

Exploitation of this vulnerability can result in unauthorized information disclosure.

Remediation

Qualcomm has notified customers about this vulnerability and provided patch instructions. For the latest patch information, device OEMs can contact Qualcomm directly.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.