ZeroHour

CVE-2025-21480

KEVmass

Incorrect Authorization in Qualcomm GPU Micronode Affecting Multiple Chipsets

CISA: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

CVSS 3.1
8.6 high
EPSS
<1%p39
Published
()
KEV added
AI analysis

CVE-2025-21480 is a memory corruption flaw caused by unauthorized command execution in the GPU micronode of Qualcomm chipsets, triggered when a specific sequence of commands is executed. A local attacker (the CVSS vector requires local access and user interaction, such as running a malicious app) could corrupt GPU memory, leading to high-impact impacts on confidentiality, integrity, and availability, though specific privilege-escalation details are not disclosed in the available data. Affected silicon spans a dozen Qualcomm chipsets and connectivity components, including Snapdragon 855 (SD855), Snapdragon 8 Gen 3 (SC8380XP), FastConnect 6200/6700/6800/6900/7800, QAM/AQT1000, QCA6391, QCM4490, QCS4490, and SM4635, meaning a wide range of Android smartphones and IoT/device platforms are potentially impacted. Qualcomm has assigned the CVE, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-03; trade press reports indicate Qualcomm fixed three zero-days, including GPU-related bugs, exploited in limited, targeted attacks via the Adreno GPU. No public proof-of-concept is known, but active exploitation is confirmed, and defenders should treat this as exploited in the wild.

What to do: Apply the June 2025 (and later) Android security bulletin/OEM patches, which carry Qualcomm's fixes, by updating affected phones and devices as vendor updates become available, and check with your device OEM whether your chipset (e.g., Snapdragon 855, 8 Gen 3, or listed FastConnect parts) is covered. Because the local attack vector likely requires a malicious app, avoid installing untrusted apps on unpatched devices as an interim mitigation. U.S. federal agencies must follow CISA BOD 22-01 required actions per the KEV entry, applying vendor mitigations or discontinuing use of affected products if mitigations are unavailable.

Affected
Qualcomm AQT1000 firmware
Qualcomm FastConnect 6200 firmware
Qualcomm FastConnect 6700 firmware
Qualcomm FastConnect 6800 firmware
Qualcomm FastConnect 6900 firmware
Qualcomm FastConnect 7800 firmware
Qualcomm QCA6391 firmware
Qualcomm QCM4490 firmware
Qualcomm QCS4490 firmware
Qualcomm SC8380XP (Snapdragon 8 Gen 3) firmware
Qualcomm SD855 (Snapdragon 855) firmware
Qualcomm SM4635 firmware
Estimated exposure
masshundreds of millions of devices (affected chipsets ship across generations of Android smartphones and connected device platforms) — Estimate based on Qualcomm's dominant share of Android handset silicon and the wide deployment of affected parts such as Snapdragon 855 (2019-2020 flagships), Snapdragon 8 Gen 3 (2024 flagships), and FastConnect connectivity chips across…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

CISA Known Exploited Vulnerability
Affected
Qualcomm Multiple Chipsets
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
qualcomm
Products
aqt1000 firmware, fastconnect 6200 firmware, fastconnect 6700 firmware, fastconnect 6800 firmware, fastconnect 6900 firmware, fastconnect 7800 firmware, qca6391 firmware, qcm4490 firmware, qcs4490 firmware, sc8380xp firmware, sd855 firmware, sm4635 firmware
Weakness
CWE-863
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news