LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-21479: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 3, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 24, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-21479 to its Known Exploited Vulnerabilities catalog on Jun 3, 2025, with a federal patch deadline of Jun 24, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing…

CVE-2025-21479 is an incorrect authorization vulnerability affecting multiple Qualcomm chipsets. It can lead to memory corruption when unauthorized commands are executed in the GPU micronode through a specific sequence of operations. For IT and security teams, this matters because Qualcomm silicon is common in mobile devices, embedded systems, and other hardware platforms; successful abuse could allow an attacker to disrupt or control GPU-related processing on affected devices.

Public detail is limited to the CISA description of the flaw class and impact. Confirm all product-specific scope, fixed firmware or software versions, and exploitation requirements against the vendor advisory before acting.

How it works

The weakness is CWE-863 (Incorrect Authorization). In this case, the chipset fails to properly enforce authorization checks for certain commands directed at the GPU micronode. An attacker who can issue a crafted sequence of commands may trigger unauthorized execution that results in memory corruption.

At a technical level, the GPU micronode is a privileged processing component. Without correct authorization, commands that should be rejected or restricted can instead reach that component and produce memory-safety failures. Exact preconditions (local versus remote access, required privileges, or user interaction) are not detailed in the available summary; treat the attack surface as whatever interfaces allow command submission to the GPU subsystem on the affected chipsets and verify those details in the vendor advisory.

Am I affected? How to find it in your systems

Qualcomm chipsets appear in smartphones, tablets, IoT devices, automotive systems, and other embedded platforms. Inventory any hardware that uses Qualcomm silicon, including mobile fleets, managed endpoints, and specialized equipment.

How to remediate

Apply the vendor-supplied mitigations or updates first. Follow the instructions in the Qualcomm or device OEM advisory for CVE-2025-21479; this typically means installing the fixed firmware, driver, or OS package that corrects the authorization check.

If mitigations are unavailable for a given product, CISA advises discontinuing use of that product.

If you can't patch immediately

Reduce exposure until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and subsequent data exposure. Known ransomware use of this CVE is not documented. If you suspect compromise, isolate the device, preserve logs, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data sets to check whether credentials or personal information associated with your organization have already appeared in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQualcomm · Multiple Chipsets
WeaknessCWE-863
Added to CISA KEVJun 3, 2025
Federal patch deadlineJun 24, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities