ZeroHour
Security Affairspublished ()ingested @securityaffairs

Google fixed two Qualcomm bugs that were actively exploited in the wild

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-21479
+2 in the same advisory: …21480 …27038
Incorrect Authorization in Qualcomm GPU Firmware Across Multiple Chipsets

CVE-2025-21479 is an incorrect authorization flaw (CWE-863) in Qualcomm chipset firmware that allows unauthorized command execution in a GPU micronode, causing memory corruption when the GPU processes a specific sequence of commands. Because the CVSS vector is local (AV:L) with user interaction required, exploitation most plausibly involves a malicious local application or process driving the GPU through the vulnerable command sequence. An attacker who successfully triggers the flaw gains high-impact confidentiality, integrity, and availability effects with scope change, meaning the compromise can extend beyond the GPU component to the broader device. Affected products span Qualcomm AQT1000, FastConnect 6200/6700/6800/6900/7800, QCA6391, QCM4490, QCS4490, Snapdragon 855 (SD855), SM4635, and SM6250 firmware, i.e., chipsets used in Android smartphones and IoT/industrial devices. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-03, and news reports describe limited, targeted Android attacks exploiting Qualcomm GPU zero-days fixed in Google's 2025 Android security updates.

Do: Apply Qualcomm's fix by installing the Android security update from June 2025 or later (or the OEM/vendor firmware update for QCM4490, QCS4490, FastConnect, and other affected chipsets), checking your device's security patch level and chipset firmware against Qualcomm's bulletin, which lists the exact fixed versions. Organizations subject to BOD 22-01 must apply vendor mitigations per CISA's KEV required action or discontinue use of affected products; there is no known public PoC, but exploitation in targeted attacks is confirmed, so prioritize patching internet-facing and user-facing Android fleets.

8.6
group max
<1% KEV
  • Qualcomm AQT1000 firmware
  • Qualcomm FastConnect 6200 firmware
  • Qualcomm FastConnect 6700 firmware
  • +9 more
masshundreds of millions of devices (estimated)
CVE-2025-48530
In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check.

In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. This could lead to remote code execution in combination with other bugs, with no additional execution privileges needed. User interaction is not needed for exploitation.

NVD description · AI analysis pending
8.1<1%
  • google android
Full article345 words · extracted from securityaffairs.com · click to collapse

Google addressed multiple Android flaws, including two Qualcomm vulnerabilities that were actively exploited in the wild.

Google released security updates to address multiple Android vulnerabilities, including two Qualcomm flaws, tracked as CVE-2025-21479 (CVSS score: 8.6) and CVE-2025-27038 (CVSS score: 7.5), that were actively exploited in the wild.

In June, Google Android Security team reported three issues, tracked as CVE-2025-21479, CVE-2025-21480, CVE-2025-27038, to Qualcomm.

“There are indications from Google Threat Analysis Group that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation.” reads the report published by the vendor. “Patches for the issues affecting the Adreno Graphics Processing Unit (GPU) driver have been made available to OEMs in May together with a strong recommendation to deploy the update on affected devices as soon as possible.”

Below are the descriptions of these vulnerabilities:

  • CVE-2025-21479 (CVSS score: 8.6) – The flaw is an Incorrect Authorization issue in the Graphics component. “Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.” reads the advisory.
  • CVE-2025-21480 (CVSS score: 8.6) – The flaw is an Incorrect Authorization issue in Graphics Windows. “Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.” reads the advisory.
  • CVE-2025-27038 (CVSS score: 7.5) – The flaw is a use-after-free issue in the Graphics component. “Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.” states the advisory.

The company did not share details about the attacks exploiting the three vulnerabilities.

In early July, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Qualcomm chipsets flaws to its Known Exploited Vulnerabilities (KEV) catalog.

The most severe flaw addressed by Google is a critical vulnerability, tracked as CVE-2025-48530, in the System component that enabled remote code execution without user interaction or extra privileges, when combined with other bugs.

The company released two Android patch levels, 2025-08-01 and 2025-08-05, with the latter including fixes from Arm and Qualcomm. Users are urged to update as soon as possible.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Android)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/180847/security/google-fixed-two-qualcomm-bugs-that-were-actively-exploited-in-the-wild.html