LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-21480: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 3, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 24, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-21480 to its Known Exploited Vulnerabilities catalog on Jun 3, 2025, with a federal patch deadline of Jun 24, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing…

CVE-2025-21480 is an incorrect authorization vulnerability affecting multiple Qualcomm chipsets. It enables unauthorized command execution in the GPU micronode when a specific sequence of commands is processed, which can result in memory corruption. For IT and security teams managing mobile, embedded, or other devices that rely on these chipsets, the issue matters because successful abuse can compromise device integrity and open paths to further control of the affected hardware.

Public detail is limited to the CISA description and the CWE classification; exact impact depends on the device firmware and configuration. Confirm all product-specific details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-863 (Incorrect Authorization). In this case, the GPU micronode fails to properly enforce authorization checks on certain commands. An attacker who can supply or influence a crafted sequence of commands may execute operations that should be restricted. The result is memory corruption within the GPU component.

No public exploit code or precise trigger sequence is provided in the available facts. Abuse would typically require the ability to interact with the GPU interface on a vulnerable chipset—possible through malicious applications, compromised drivers, or other local or privileged access depending on the platform. Teams should treat the vulnerability as a local or near-local memory-corruption risk until the vendor advisory supplies more precise attack surface information.

Am I affected? How to find it in your systems

Qualcomm chipsets appear in a wide range of smartphones, tablets, IoT devices, automotive systems, and other embedded platforms. Inventory efforts should focus on hardware that uses Qualcomm SoCs or discrete GPU components.

If your environment includes cloud-hosted or managed services that rely on these chipsets, also apply the applicable BOD 22-01 guidance referenced by CISA.

How to remediate

The primary remediation is to apply the mitigations and firmware or software updates issued by Qualcomm or the device manufacturer, exactly as described in the vendor advisory. Follow the CISA required action: apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Document the update status of every affected asset for audit and compliance purposes.

If you can't patch immediately

Until the vendor update can be deployed, reduce exposure with compensating controls that limit access to the vulnerable GPU path.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to device compromise and subsequent data exposure. Known ransomware use is not documented for CVE-2025-21480, but any successful memory-corruption attack can still enable credential theft, lateral movement, or data exfiltration. Review device logs and network telemetry for signs of post-exploitation activity. Readers can run a free exposure scan of their email addresses against known breach data sets to determine whether associated accounts have already appeared in public breach collections, then force password resets and enable multi-factor authentication where appropriate.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQualcomm · Multiple Chipsets
WeaknessCWE-863
Added to CISA KEVJun 3, 2025
Federal patch deadlineJun 24, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities