• News/
  • https://www.bleepingcomputer.com/news/security/qualcomm-fixes-three-adreno-gpu-zero-days-exploited-in-attacks/

Qualcomm fixes three Adreno GPU zero-days exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jun 2, 2025
·
Updated

Qualcomm has released security patches for three zero-day vulnerabilities in the Adreno Graphics Processing Unit (GPU) driver that impact dozens of chipsets and are actively exploited in targeted attacks. The company says two critical flaws (tracked as CVE-2025-21479 and CVE-2025-21480) were reported through the Google Android Security team in late January, and a third high-severity vulnerability (CVE-2025-27038) was reported in March. The first two are both Graphics framework incorrect authorization weaknesses that can lead to memory corruption because of unauthorized command execution in the GPU micronode while executing a specific sequence of commands, while CVE-2025-27038 is a use-after-free causing memory corruption while rendering graphics using Adreno GPU drivers in Chrome. "There are indications from Google Threat Analysis Group that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation," Qualcomm warned in a Monday advisory. "Patches for the issues affecting the Adreno Graphics Processing Unit (GPU) driver have been made available to OEMs in May together with a strong recommendation to deploy the update on affected devices as soon as possible." This month, Qualcomm has also addressed a buffer over-read in Data Network Stack & Connectivity (CVE-2024-53026) that unauthenticated attackers can exploit to gain access to restricted information using invalid RTCP packets sent during a VoLTE/VoWiFi IMS calls. In October, the company fixe...

Read full article

Affected Software

4 affected components
Qualcomm Adreno Graphics Processing Unit (GPU) driver
Qualcomm Data Network Stack & Connectivity
Qualcomm Adreno GPU drivers in Chrome
Qualcomm Adreno Graphics Processing Unit (GPU) driver
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Qualcomm's release of security patches for three zero-day vulnerabilities in their Adreno GPU driver.

2

What vulnerabilities have been identified in this article?

The article identifies two critical zero-day vulnerabilities tracked as CVE-2025-21479 and CVE-2025-21480.

3

How are these vulnerabilities being exploited?

The vulnerabilities have been actively exploited in targeted attacks against devices using the affected Adreno GPU driver.

4

Which products or software are affected by these vulnerabilities?

The affected software includes the Qualcomm Adreno GPU driver, Qualcomm Data Network Stack & Connectivity, and Qualcomm Adreno GPU drivers in Chrome.

5

What should users do to protect themselves from these vulnerabilities?

Users should apply the latest security patches released by Qualcomm to mitigate the risks associated with these vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203