Memory corruption vulnerability in Qualcomm Snapdragon GPU micronode allowing unauthorized command execution. Despite being in CISA KEV, this is a local privilege escalation requiring user interaction on mobile/IoT devices, not an internet-facing server vulnerability.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: USER_INTERACTION
CVE Published: 2025-06-03
Added to CISA KEV: 2025-06-03 0 DAY BETWEEN CVE AND KEV
CVE-2025-21480 is a critical security vulnerability affecting Qualcomm's Adreno GPU drivers [2]. Below is a summary of the known details regarding this vulnerability.
There are still no details on how these shortcomings have been weaponized in real-world attacks, but Qualcomm noted at the time that "there are indications from Google Threat Analysis Group that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation." ... Google f…
CVEs. CVE-2025-21480. Proof of exploitExploited in the wild.CVE-2025-21480 is a critical vulnerability in Qualcomm's Adreno GPU drivers related to incorrect authorization, allowing unauthorized command execution that can lead to memory corruption and potential data breaches. It has been confirmed to…
To fix CVE-2025-21480, users should update their devices with the latest firmware patches provided by Qualcomm. What are the potential impacts of exploiting CVE-2025-21480?CVE-2025-21480 affects multiple Qualcomm chipsets that utilize the Adreno GPU architecture. How can I mitigate the risks associa…
CVE-2025-21480 Detail Description Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. ... CVE-2025-21480 Detail. Description. Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence…
... CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation. Patches for the issues affecting the Adreno Graphics Processing ...
Patches for the issues affecting the Adreno Graphics Processing Unit (GPU) driver have been made available to OEMs in May together with a strong ...