On June 2, 2025, Qualcomm released critical security updates addressing three zero-day vulnerabilities in its Adreno Graphics Processing Unit (GPU) drivers. These vulnerabilities, identified as CVE-2025-21479, CVE-2025-21480, and CVE-2025-27038, have been actively exploited in targeted attacks against Android devices.

Overview of the Vulnerabilities

The first two vulnerabilities, CVE-2025-21479 and CVE-2025-21480, both carry a CVSS score of 8.6, indicating high severity. They are characterized as incorrect authorization flaws within the GPU’s graphics component, potentially leading to memory corruption through unauthorized command execution in the GPU microcode.

The third vulnerability, CVE-2025-27038, has a CVSS score of 7.5 and is classified as a use-after-free issue in the graphics component. This flaw could result in memory corruption during graphics rendering using Adreno GPU drivers, particularly when rendering graphics in the Chrome browser.

Discovery and Disclosure

These vulnerabilities were responsibly disclosed to Qualcomm by the Google Android Security team. The first two were reported in late January 2025, while the third was reported in March 2025. Google’s Threat Analysis Group has indicated that these vulnerabilities may be under limited, targeted exploitation.

Impact and Exploitation

While specific details about the exploitation methods and the threat actors involved have not been disclosed, the nature of these vulnerabilities suggests they could be valuable to commercial spyware vendors and advanced persistent threat (APT) groups. Similar vulnerabilities in Qualcomm chipsets have previously been exploited by spyware vendors such as Variston and Cy4Gate.

The widespread use of Qualcomm’s Adreno GPU technology across various smartphone manufacturers, including Samsung, Google, Xiaomi, and OnePlus, amplifies the potential impact of these vulnerabilities.

Patching and Recommendations

Qualcomm has made patches for these vulnerabilities available to Original Equipment Manufacturers (OEMs) as of May 2025, accompanied by a strong recommendation for immediate deployment on affected devices. The company urges users to contact their device manufacturers for information regarding the availability of these security updates.

In addition to these GPU-related vulnerabilities, Qualcomm’s June 2025 security bulletin also addresses other high-severity issues affecting the data network stack, WLAN HAL, and Bluetooth host components.

Conclusion

The discovery and patching of these zero-day vulnerabilities underscore the ongoing challenges in securing mobile devices against sophisticated attacks. Users are advised to stay informed about security updates from their device manufacturers and to apply patches promptly to mitigate potential risks.

For more detailed information, please refer to Qualcomm’s official security bulletin: https://docs.qualcomm.com/product/publicresources/securitybulletin

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *