• News/
  • https://www.zdnet.com/article/qualcomm-patches-three-exploited-security-flaws-but-you-could-still-be-vulnerable/

Qualcomm patches three exploited security flaws, but you could still be vulnerable

ZDNet
·
Lance Whitney
·
Published Jun 4, 2025
·
Updated

Wireless tech maker Qualcomm has patched three zero-day security flaws that it says may have already been exploited in the wild. In a security bulletin published Monday, the company revealed that the issue affects a driver for the Adreno Graphics Processing Unit, which is found in devices powered by its Snapdragon processors. Also: The default TV setting you should turn off ASAP - and why pros do the same "There are indications from Google Threat Analysis Group that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation," Qualcomm said in the advisory. "Patches for the issues affecting the Adreno Graphics Processing Unit (GPU) driver have been made available to OEMs in May, together with a strong recommendation to deploy the update on affected devices as soon as possible. Please contact your device manufacturer for more information on the patch status about specific devices." Qualcomm makes the processors, chipsets, modems, and other tech that go into smartphones, laptops, and other consumer gear. This means that patching its own components is only half the battle. Device makers must also apply patches to their products, a process over which consumers have little or no control. Attributing the discovery to researchers at Google Threat Analysis Group, Qualcomm cited the three security flaws via their CVE numbers. CVE-2025-21479, CVE-2025-21480, and CVE-2025-27038 all point to a memory corruption issue through which hackers can run unauthoriz...

Read full article

Affected Software

4 affected components
Qualcomm Adreno Graphics Processing Unit
Qualcomm Snapdragon processors
Qualcomm Adreno Graphics Processing Unit
Qualcomm Snapdragon
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What specific vulnerabilities does the article discuss?

The article discusses three zero-day security flaws related to Qualcomm's Adreno Graphics Processing Unit drivers.

2

How does Qualcomm classify the security flaws mentioned in the article?

Qualcomm classifies the security flaws as zero-day vulnerabilities that may have been exploited in the wild.

3

Which devices are primarily affected by these security flaws?

The security flaws affect devices powered by Qualcomm Snapdragon processors that utilize the Adreno Graphics Processing Unit.

4

What steps has Qualcomm taken in response to these vulnerabilities?

Qualcomm has released patches to address the three zero-day security flaws identified in their security bulletin.

5

Are users guaranteed to be protected after applying the patches provided by Qualcomm?

No, the article indicates that even after applying the patches, users may still be vulnerable to these security issues.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203