CVE-2025-27038
KEVmassUse-After-Free in Qualcomm Adreno GPU Drivers Affects Multiple Chipsets
CISA: Qualcomm Multiple Chipsets Use-After-Free Vulnerability
CVE-2025-27038 is a use-after-free (CWE-416) in the graphics path of Qualcomm Adreno GPU drivers, causing memory corruption while rendering graphics in the Chrome browser. It is triggered when a user (no privileges required) loads attacker-influenced web content in Chrome on a device with an affected chipset and the GPU driver frees memory that is still in use during rendering; successful exploitation carries high-impact confidentiality, integrity, and availability consequences, potentially enabling code execution or information disclosure on the device. Any device built on the listed Qualcomm chipsets — including FastConnect 7800, QCM6125/QCS6125, QCM8550/QCS8550, and the listed connectivity (AR8031, QCA2066, QCA6391, QCN9011/QCN9012) and audio (CSRA6620/CSRA6640) parts — is potentially affected, with fixed versions per Qualcomm's advisory. The flaw is being actively exploited in limited, targeted Android attacks according to Google and Qualcomm, and CISA added it to the Known Exploited Vulnerabilities catalog on June 3, 2025. It was addressed in Qualcomm's 2025 updates and Google's June 2025 Android security bulletin; no public proof-of-concept is known and ransomware use is unknown.
What to do: Apply the June 2025 (or later) Android security patch set from your device vendor and keep Chrome current, since the flaw is exercised through Chrome rendering on Adreno GPUs. For IoT, networking, or embedded products built on the listed Qualcomm chipsets, obtain the corresponding Qualcomm firmware fixes from the product vendor per Qualcomm's advisory. Organizations covered by BOD 22-01 should remediate by the KEV due date CISA assigned or discontinue use of affected products.
| Qualcomm AR8031 firmware | — |
| Qualcomm CSRA6620 firmware | — |
| Qualcomm CSRA6640 firmware | — |
| Qualcomm FastConnect 7800 firmware | — |
| Qualcomm QCA2066 firmware | — |
| Qualcomm QCA6391 firmware | — |
| Qualcomm QCM6125 firmware | — |
| Qualcomm QCM8550 firmware | — |
| Qualcomm QCN9011 firmware | — |
| Qualcomm QCN9012 firmware | — |
| Qualcomm QCS6125 firmware | — |
| Qualcomm QCS8550 firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
- Affected
- Qualcomm Multiple Chipsets
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- qualcomm
- Products
- ar8031 firmware, csra6620 firmware, csra6640 firmware, fastconnect 7800 firmware, qca2066 firmware, qca6391 firmware, qcm6125 firmware, qcm8550 firmware, qcn9011 firmware, qcn9012 firmware, qcs6125 firmware, qcs8550 firmware
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H