CVE-2025-21480

Published Jun 3, 2025

Last updated 3 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-21480 is an incorrect authorization vulnerability found in Qualcomm's Adreno GPU driver, specifically within the Graphics component. This flaw can lead to memory corruption due to unauthorized command execution in the GPU microcode when a specific sequence of commands is processed. The vulnerability is one of three zero-day flaws that were actively exploited in targeted attacks. Patches for this issue have been made available to OEMs, with a strong recommendation to deploy the update on affected devices as soon as possible.

Description
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Source
product-security@qualcomm.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.6
Impact score
6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
Exploit added on
Jun 3, 2025
Exploit action due
Jun 24, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

product-security@qualcomm.com
CWE-863

Social media

Hype score
Not currently trending
  1. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2025-21480 #Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability https://t.co/B1etdHUtIq

    @ScyScan

    5 Jun 2025

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🛡️ We added Qualcomm vulnerabilities CVE-2025-21479, CVE-2025-21480 & CVE-2025-27038—impacting multiple chipsets—to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/aEBiHHlS7W & apply mitigations to protect your org from cyberattacks. https://t.co/

    @NETFIXERTECH

    4 Jun 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Actively exploited CVE : CVE-2025-21480

    @transilienceai

    4 Jun 2025

    74 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログに3件の追加。クアルコムAderno GPUで修正されたCVE-2025-21479、CVE-2025-21480、CVE-2025-27038。対処期限は通常の6/24でランサムウ

    @__kokumoto

    3 Jun 2025

    714 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 🛡️ We added Qualcomm vulnerabilities CVE-2025-21479, CVE-2025-21480 & CVE-2025-27038—impacting multiple chipsets—to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. https://t.co/

    @CISACyber

    3 Jun 2025

    5333 Impressions

    12 Retweets

    32 Likes

    2 Bookmarks

    1 Reply

    1 Quote

  6. Qualcomm fixed three zero-days exploited in limited and targeted attacks CVE-2025-21479, CVE-2025-21480, and CVE-2025-27038 —exploited in limited, targeted attacks, as reported by Google’s Android Security and Threat Analysis teams. The first two (CVSS 8.6) involve incorrect

    @dCypherIO

    3 Jun 2025

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. [CVE-2025-21480: HIGH] Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.#cve,CVE-2025-21480,#cybersecurity https://t.co/QTYRfowoVS https://t.co/IVe4gWbL0h

    @CveFindCom

    3 Jun 2025

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. ⚠️Qualcomm Adreno GPU 0-Day Vulnerabilities Exploited to Attack Android Users Read more: https://t.co/ZwrKSRIKUS 📌CVE-2025-21479 📌CVE-2025-21480 📌CVE-2025-27038 Mobile chipmaker Qualcomm has issued urgent security patches for three critical zero-day vulnerabilitie

    @The_Cyber_News

    2 Jun 2025

    416 Impressions

    2 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. ⚠️Actualizaciones de seguridad de Qualcomm ❗CVE-2025-21479 ❗CVE-2025-21480 ❗CVE-2025-27038 ➡️Más info: https://t.co/vSdtuBR8xQ https://t.co/BaZy1EnwaJ

    @CERTpy

    2 Jun 2025

    125 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 Qualcomm just patched 3 zero-days actively exploited in the wild—two rated CVSS 8.6. ▶ CVE-2025-21479 ▶ CVE-2025-21480 ▶ CVE-2025-27038 👀 A twist? Similar bugs were used by spyware vendors like Variston and Cy4Gate. More here: https://t.co/FtxbN7hPcs

    @TheHackersNews

    2 Jun 2025

    13501 Impressions

    69 Retweets

    142 Likes

    23 Bookmarks

    1 Reply

    1 Quote

  11. Qualcomm June 2025 Security Bulletin https://t.co/pD7SaUzvR9 "There are indications from Google TAG that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation" https://t.co/7PXRdJk1IS

    @xvonfers

    2 Jun 2025

    15390 Impressions

    9 Retweets

    38 Likes

    20 Bookmarks

    12 Replies

    2 Quotes

Configurations