CVE-2025-21480
KEVmassIncorrect Authorization in Qualcomm GPU Micronode Affecting Multiple Chipsets
CISA: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
CVE-2025-21480 is a memory corruption flaw caused by unauthorized command execution in the GPU micronode of Qualcomm chipsets, triggered when a specific sequence of commands is executed. A local attacker (the CVSS vector requires local access and user interaction, such as running a malicious app) could corrupt GPU memory, leading to high-impact impacts on confidentiality, integrity, and availability, though specific privilege-escalation details are not disclosed in the available data. Affected silicon spans a dozen Qualcomm chipsets and connectivity components, including Snapdragon 855 (SD855), Snapdragon 8 Gen 3 (SC8380XP), FastConnect 6200/6700/6800/6900/7800, QAM/AQT1000, QCA6391, QCM4490, QCS4490, and SM4635, meaning a wide range of Android smartphones and IoT/device platforms are potentially impacted. Qualcomm has assigned the CVE, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-03; trade press reports indicate Qualcomm fixed three zero-days, including GPU-related bugs, exploited in limited, targeted attacks via the Adreno GPU. No public proof-of-concept is known, but active exploitation is confirmed, and defenders should treat this as exploited in the wild.
What to do: Apply the June 2025 (and later) Android security bulletin/OEM patches, which carry Qualcomm's fixes, by updating affected phones and devices as vendor updates become available, and check with your device OEM whether your chipset (e.g., Snapdragon 855, 8 Gen 3, or listed FastConnect parts) is covered. Because the local attack vector likely requires a malicious app, avoid installing untrusted apps on unpatched devices as an interim mitigation. U.S. federal agencies must follow CISA BOD 22-01 required actions per the KEV entry, applying vendor mitigations or discontinuing use of affected products if mitigations are unavailable.
| Qualcomm AQT1000 firmware | — |
| Qualcomm FastConnect 6200 firmware | — |
| Qualcomm FastConnect 6700 firmware | — |
| Qualcomm FastConnect 6800 firmware | — |
| Qualcomm FastConnect 6900 firmware | — |
| Qualcomm FastConnect 7800 firmware | — |
| Qualcomm QCA6391 firmware | — |
| Qualcomm QCM4490 firmware | — |
| Qualcomm QCS4490 firmware | — |
| Qualcomm SC8380XP (Snapdragon 8 Gen 3) firmware | — |
| Qualcomm SD855 (Snapdragon 855) firmware | — |
| Qualcomm SM4635 firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
- Affected
- Qualcomm Multiple Chipsets
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- qualcomm
- Products
- aqt1000 firmware, fastconnect 6200 firmware, fastconnect 6700 firmware, fastconnect 6800 firmware, fastconnect 6900 firmware, fastconnect 7800 firmware, qca6391 firmware, qcm4490 firmware, qcs4490 firmware, sc8380xp firmware, sd855 firmware, sm4635 firmware
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H