Wireless tech maker Qualcomm has patched three zero-day security flaws that it says may have already been exploited in the wild. In a security bulletin published Monday, the company revealed that the issue affects a driver for the Adreno Graphics Processing Unit, which is found in devices powered by its Snapdragon processors. Also: The default TV setting you should turn off ASAP - and why pros do the same "There are indications from Google Threat Analysis Group that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation," Qualcomm said in the advisory. "Patches for the issues affecting the Adreno Graphics Processing Unit (GPU) driver have been made available to OEMs in May, together with a strong recommendation to deploy the update on affected devices as soon as possible. Please contact your device manufacturer for more information on the patch status about specific devices." Qualcomm makes the processors, chipsets, modems, and other tech that go into smartphones, laptops, and other consumer gear. This means that patching its own components is only half the battle. Device makers must also apply patches to their products, a process over which consumers have little or no control. Attributing the discovery to researchers at Google Threat Analysis Group, Qualcomm cited the three security flaws via their CVE numbers. CVE-2025-21479, CVE-2025-21480, and CVE-2025-27038 all point to a memory corruption issue through which hackers can run unauthoriz...
Qualcomm patches three exploited security flaws, but you could still be vulnerable
ZDNet
·Lance Whitney
·Published Jun 4, 2025
·Updated
Affected Software
4 affected components
Qualcomm Adreno Graphics Processing Unit
Qualcomm Snapdragon processors
Qualcomm Adreno Graphics Processing Unit
Qualcomm Snapdragon
Frequently Asked Questions
1
What specific vulnerabilities does the article discuss?
The article discusses three zero-day security flaws related to Qualcomm's Adreno Graphics Processing Unit drivers.
2
How does Qualcomm classify the security flaws mentioned in the article?
Qualcomm classifies the security flaws as zero-day vulnerabilities that may have been exploited in the wild.
3
Which devices are primarily affected by these security flaws?
The security flaws affect devices powered by Qualcomm Snapdragon processors that utilize the Adreno Graphics Processing Unit.
4
What steps has Qualcomm taken in response to these vulnerabilities?
Qualcomm has released patches to address the three zero-day security flaws identified in their security bulletin.
5
Are users guaranteed to be protected after applying the patches provided by Qualcomm?
No, the article indicates that even after applying the patches, users may still be vulnerable to these security issues.