Google has rolled out its August 2025 Android Security Update, addressing six vulnerabilities in total—including three serious bugs in Qualcomm components that were reportedly exploited in targeted attacks.
⚠️ The Exploited Qualcomm Flaws
Two critical issues—for total of three Qualcomm CVEs—are at the heart of this update:
- CVE‑2025‑21479: An incorrect authorization bug in the Adreno GPU graphics microcode, allowing unauthorized commands to corrupt memory, rated CVSS 8.6
- CVE‑2025‑27038: A use‑after‑free vulnerability within Adreno GPU drivers affecting Chrome’s rendering operations, causing possible memory corruption, rated CVSS 7.5.
- CVE‑2025‑21480: A related flaw also with a CVSS 8.6 rating, disclosed alongside CVE‑2025‑21479, affecting similar graphics authorization mechanisms.
Qualcomm issued these patches in June 2025, urging OEMs to deploy updates immediately due to “indications from Google Threat Analysis Group that these vulnerabilities may be under limited, targeted exploitation”.
📦 Insights from the Android Security Bulletin
The Android Security Bulletin (August 2025) reveals:
- Patch levels of 2025‑08‑01 and 2025‑08‑05 are now available—devices running 08‑05 or newer include all fixes from the earlier level, plus additional issues.
- CVE‑2025‑21479 is classified as critical and falls under Qualcomm’s closed‑source component section.
- CVE‑2025‑27038 is marked high and tied to Qualcomm’s Display subcomponent efforts.
The bulletin further highlights a separate critical System‑level remote code execution (RCE) vulnerability—CVE‑2025‑48530—which requires no user interaction for exploitation and affects Android 16 devices.
🛡 Why This Matters
This update is especially concerning because:
- Active exploitation: The Qualcomm flaws (CVE‑2025‑21479, ‑21480, ‑27038) were known to be exploited in targeted attacks—i.e. real-world abuse, not just theoretical risk.
- High severity: With CVSS ratings up to 8.6, these flaws can lead to significant system memory corruption and potential device compromise.
- OS‑level exposure: The System‑component RCE bug (CVE‑2025‑48530) is both critical and “user‑interaction = not needed,” meaning no victim action would be required to be targeted.
- Update immediately: Install the 2025‑08‑05 Android security patch—or 08‑01 at minimum—as provided by your device OEM or through Google Play system updates. This timeline ensures protection against all six patched vulnerabilities.
- Verify patch level: On your Android device, open Settings › System › About phone › Security patch level to check the installed date (should read 2025‑08‑05 or newer).
- Update Chrome and other apps: Since one of the bugs affects GPU drivers in Chrome rendering, ensure apps like Chrome are running their latest versions.
- Earlier in April 2025, Google also released firmware updates covering 62 Android flaws, including two critically exploited zero‑day kernel bugs (CVE‑2024‑53197 and CVE‑2024‑53150), which had been weaponized in targeting activists via Cellebrite tools.
- In June 2025, the Qualcomm6 June bulletin addressed the same trio of Adreno GPU zero‑days previously patched in Android via OEM releases—demonstrating a continued trend of serious GPU‑level flaws under active exploitation.
- Earlier patch cycles—such as those in March and February 2025—also addressed actively exploited vulnerabilities in both the Android framework and kernel components.
🧩 In Summary
The August 2025 Android security update fixes six vulnerabilities, including:
- Three serious Qualcomm Adreno GPU bugs (CVE‑2025‑21479, ‑21480, ‑27038) with confirmed or suspected limited real-world exploitation.
- A critical system-level RCE flaw (CVE‑2025‑48530) requiring no user action.
- Additional elevation-of-privilege and information-disclosure issues.
The urgency is warranted—these vulnerabilities have real-world impact potential, particularly in targeted intrusion scenarios. If your device is still supported, installing the August patch should be a top priority to maintain security and resilience against growing cyber threats.
Please subscribe to the Newsletter so that you do not miss any critical update
