ZeroHour

CVE-2025-21479

KEVmass

Incorrect Authorization in Qualcomm GPU Firmware Across Multiple Chipsets

CISA: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

CVSS 3.1
8.6 high
EPSS
<1%p56
Published
()
KEV added
AI analysis

CVE-2025-21479 is an incorrect authorization flaw (CWE-863) in Qualcomm chipset firmware that allows unauthorized command execution in a GPU micronode, causing memory corruption when the GPU processes a specific sequence of commands. Because the CVSS vector is local (AV:L) with user interaction required, exploitation most plausibly involves a malicious local application or process driving the GPU through the vulnerable command sequence. An attacker who successfully triggers the flaw gains high-impact confidentiality, integrity, and availability effects with scope change, meaning the compromise can extend beyond the GPU component to the broader device. Affected products span Qualcomm AQT1000, FastConnect 6200/6700/6800/6900/7800, QCA6391, QCM4490, QCS4490, Snapdragon 855 (SD855), SM4635, and SM6250 firmware, i.e., chipsets used in Android smartphones and IoT/industrial devices. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-03, and news reports describe limited, targeted Android attacks exploiting Qualcomm GPU zero-days fixed in Google's 2025 Android security updates.

What to do: Apply Qualcomm's fix by installing the Android security update from June 2025 or later (or the OEM/vendor firmware update for QCM4490, QCS4490, FastConnect, and other affected chipsets), checking your device's security patch level and chipset firmware against Qualcomm's bulletin, which lists the exact fixed versions. Organizations subject to BOD 22-01 must apply vendor mitigations per CISA's KEV required action or discontinue use of affected products; there is no known public PoC, but exploitation in targeted attacks is confirmed, so prioritize patching internet-facing and user-facing Android fleets.

Affected
Qualcomm AQT1000 firmware
Qualcomm FastConnect 6200 firmware
Qualcomm FastConnect 6700 firmware
Qualcomm FastConnect 6800 firmware
Qualcomm FastConnect 6900 firmware
Qualcomm FastConnect 7800 firmware
Qualcomm QCA6391 firmware
Qualcomm QCM4490 firmware
Qualcomm QCS4490 firmware
Qualcomm SD855 (Snapdragon 855) firmware
Qualcomm SM4635 firmware
Qualcomm SM6250 firmware
Estimated exposure
masshundreds of millions of devices (estimated) — The listed chipsets ship across flagship and mid-range Android smartphones (e.g., Snapdragon 855-powered 2019-2020 flagships), Wi-Fi/Bluetooth FastConnect combo parts, and QCM/QCS IoT/industrial modules, so the aggregate installed base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

CISA Known Exploited Vulnerability
Affected
Qualcomm Multiple Chipsets
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
qualcomm
Products
aqt1000 firmware, fastconnect 6200 firmware, fastconnect 6700 firmware, fastconnect 6900 firmware, fastconnect 7800 firmware, fastconnect 6800 firmware, qca6391 firmware, qcm4490 firmware, qcs4490 firmware, sd855 firmware, sm4635 firmware, sm6250 firmware
Weakness
CWE-863
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news