CVE-2025-21479

Published Jun 3, 2025

Last updated 3 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-21479 is an incorrect authorization vulnerability found in the Graphics component of Qualcomm's Adreno GPU driver. This flaw can lead to memory corruption due to unauthorized command execution in the GPU microcode when a specific sequence of commands is processed. Successful exploitation of CVE-2025-21479 could allow attackers to execute unauthorized commands, potentially corrupting system memory. Qualcomm has released patches for this vulnerability and recommends that OEMs deploy the updates to affected devices as soon as possible. There are indications that this vulnerability may be under limited, targeted exploitation.

Description
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Source
product-security@qualcomm.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.6
Impact score
6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
Exploit added on
Jun 3, 2025
Exploit action due
Jun 24, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

product-security@qualcomm.com
CWE-863

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

22

  1. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2025-21479 #Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability https://t.co/3ZYCe79nN9

    @ScyScan

    5 Jun 2025

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Google’ın Android güvenlik ekibi, bazı Snapdragon çiplerinde üç kritik güvenlik açığı buldu. Qualcomm, bu açıkların hedefli siber saldırılarda kullanıldığını doğruladı ve mayıs ayında üreticilere yama gönderdi. Açıklar CVE-2025-21479, 21480 ve 2703

    @webtekno

    5 Jun 2025

    9853 Impressions

    1 Retweet

    11 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  3. Actively exploited CVE : CVE-2025-21479

    @transilienceai

    5 Jun 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Actively exploited CVE : CVE-2025-21479

    @transilienceai

    5 Jun 2025

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 🛡️ We added Qualcomm vulnerabilities CVE-2025-21479, CVE-2025-21480 & CVE-2025-27038—impacting multiple chipsets—to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/aEBiHHlS7W & apply mitigations to protect your org from cyberattacks. https://t.co/

    @NETFIXERTECH

    4 Jun 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログに3件の追加。クアルコムAderno GPUで修正されたCVE-2025-21479、CVE-2025-21480、CVE-2025-27038。対処期限は通常の6/24でランサムウ

    @__kokumoto

    3 Jun 2025

    714 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. 🛡️ We added Qualcomm vulnerabilities CVE-2025-21479, CVE-2025-21480 & CVE-2025-27038—impacting multiple chipsets—to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. https://t.co/

    @CISACyber

    3 Jun 2025

    5333 Impressions

    12 Retweets

    32 Likes

    2 Bookmarks

    1 Reply

    1 Quote

  8. Qualcomm fixed three zero-days exploited in limited and targeted attacks CVE-2025-21479, CVE-2025-21480, and CVE-2025-27038 —exploited in limited, targeted attacks, as reported by Google’s Android Security and Threat Analysis teams. The first two (CVSS 8.6) involve incorrect

    @dCypherIO

    3 Jun 2025

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2025-21479 Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. https://t.co/a0CobVX3ue

    @CVEnew

    3 Jun 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. [CVE-2025-21479: HIGH] Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.#cve,CVE-2025-21479,#cybersecurity https://t.co/FTYKsUYmwf https://t.co/X4bz5geftH

    @CveFindCom

    3 Jun 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. تحذير أمني عاجل من Qualcomm 3 ثغرات خطيرة من نوع Zero-Day تم استغلالها بهجمات تستهدف مستخدمي أجهزة بمعالجات Adreno GPU، أبرزها CVE-2025-21479. كوالكوم أرسلت تحديثات للمصنّعي

    @mjbtechtips

    2 Jun 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. ⚠️Qualcomm Adreno GPU 0-Day Vulnerabilities Exploited to Attack Android Users Read more: https://t.co/ZwrKSRIKUS 📌CVE-2025-21479 📌CVE-2025-21480 📌CVE-2025-27038 Mobile chipmaker Qualcomm has issued urgent security patches for three critical zero-day vulnerabilitie

    @The_Cyber_News

    2 Jun 2025

    416 Impressions

    2 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Qualcommは、限定的かつ標的型の攻撃で悪用された3件のゼロデイ脆弱性に対するセキュリティパッチを提供した。 これらはGoogle Android Securityチームにより報告されたもので、CVE-2025-21479および21480(CVSS

    @yousukezan

    2 Jun 2025

    2333 Impressions

    0 Retweets

    10 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  14. ⚠️Actualizaciones de seguridad de Qualcomm ❗CVE-2025-21479 ❗CVE-2025-21480 ❗CVE-2025-27038 ➡️Más info: https://t.co/vSdtuBR8xQ https://t.co/BaZy1EnwaJ

    @CERTpy

    2 Jun 2025

    125 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 Qualcomm just patched 3 zero-days actively exploited in the wild—two rated CVSS 8.6. ▶ CVE-2025-21479 ▶ CVE-2025-21480 ▶ CVE-2025-27038 👀 A twist? Similar bugs were used by spyware vendors like Variston and Cy4Gate. More here: https://t.co/FtxbN7hPcs

    @TheHackersNews

    2 Jun 2025

    13501 Impressions

    69 Retweets

    142 Likes

    23 Bookmarks

    1 Reply

    1 Quote

  16. Qualcomm June 2025 Security Bulletin https://t.co/pD7SaUzvR9 "There are indications from Google TAG that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation" https://t.co/7PXRdJk1IS

    @xvonfers

    2 Jun 2025

    15390 Impressions

    9 Retweets

    38 Likes

    20 Bookmarks

    12 Replies

    2 Quotes

Configurations