CVE-2025-21479
KEVmassIncorrect Authorization in Qualcomm GPU Firmware Across Multiple Chipsets
CISA: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
CVE-2025-21479 is an incorrect authorization flaw (CWE-863) in Qualcomm chipset firmware that allows unauthorized command execution in a GPU micronode, causing memory corruption when the GPU processes a specific sequence of commands. Because the CVSS vector is local (AV:L) with user interaction required, exploitation most plausibly involves a malicious local application or process driving the GPU through the vulnerable command sequence. An attacker who successfully triggers the flaw gains high-impact confidentiality, integrity, and availability effects with scope change, meaning the compromise can extend beyond the GPU component to the broader device. Affected products span Qualcomm AQT1000, FastConnect 6200/6700/6800/6900/7800, QCA6391, QCM4490, QCS4490, Snapdragon 855 (SD855), SM4635, and SM6250 firmware, i.e., chipsets used in Android smartphones and IoT/industrial devices. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-03, and news reports describe limited, targeted Android attacks exploiting Qualcomm GPU zero-days fixed in Google's 2025 Android security updates.
What to do: Apply Qualcomm's fix by installing the Android security update from June 2025 or later (or the OEM/vendor firmware update for QCM4490, QCS4490, FastConnect, and other affected chipsets), checking your device's security patch level and chipset firmware against Qualcomm's bulletin, which lists the exact fixed versions. Organizations subject to BOD 22-01 must apply vendor mitigations per CISA's KEV required action or discontinue use of affected products; there is no known public PoC, but exploitation in targeted attacks is confirmed, so prioritize patching internet-facing and user-facing Android fleets.
| Qualcomm AQT1000 firmware | — |
| Qualcomm FastConnect 6200 firmware | — |
| Qualcomm FastConnect 6700 firmware | — |
| Qualcomm FastConnect 6800 firmware | — |
| Qualcomm FastConnect 6900 firmware | — |
| Qualcomm FastConnect 7800 firmware | — |
| Qualcomm QCA6391 firmware | — |
| Qualcomm QCM4490 firmware | — |
| Qualcomm QCS4490 firmware | — |
| Qualcomm SD855 (Snapdragon 855) firmware | — |
| Qualcomm SM4635 firmware | — |
| Qualcomm SM6250 firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
- Affected
- Qualcomm Multiple Chipsets
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- qualcomm
- Products
- aqt1000 firmware, fastconnect 6200 firmware, fastconnect 6700 firmware, fastconnect 6900 firmware, fastconnect 7800 firmware, fastconnect 6800 firmware, qca6391 firmware, qcm4490 firmware, qcs4490 firmware, sd855 firmware, sm4635 firmware, sm6250 firmware
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H