Qualcomm fixes three Adreno GPU zero-days exploited in attacks

Qualcomm Patches Three Actively Exploited GPU Vulnerabilities Affecting Android Devices
Photo: BleepingComputer

Qualcomm Patches Three Actively Exploited GPU Vulnerabilities Affecting Android Devices

Qualcomm has issued security updates to address three zero-day vulnerabilities in its Adreno GPU drivers that were actively exploited in targeted attacks. Two of the critical vulnerabilities (CVE-2025-21479 and CVE-2025-21480), reported by the Google Android Security team in January 2025, involve improper authorization in the graphics framework, allowing memory corruption due to unauthorized GPU command execution. A third high-severity flaw (CVE-2025-27038), reported in March, is a use-after-free issue that causes memory corruption when rendering graphics in Chrome.

According to Qualcomm, all three vulnerabilities have been confirmed as being under limited, targeted exploitation, based on intelligence from Google’s Threat Analysis Group (TAG). Patches were distributed to OEMs in May, along with recommendations for prompt deployment.

In addition to these GPU flaws, Qualcomm also patched a buffer over-read vulnerability (CVE-2024-53026) in its Data Network Stack, which could let unauthenticated attackers access restricted information during VoLTE or VoWiFi calls. The report also references a previous exploit (CVE-2024-43047) used by Serbian authorities with Cellebrite tools to access Android devices, further highlighting persistent threats against device security.

Qualcomm continues to address numerous vulnerabilities in its chipsets, as attackers increasingly target mobile hardware components to bypass software protections and compromise personal data.

Leave a Reply

Your email address will not be published. Required fields are marked *