LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-27038: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 3, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 24, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-27038 to its Known Exploited Vulnerabilities catalog on Jun 3, 2025, with a federal patch deadline of Jun 24, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

CVE-2025-27038 is a use-after-free vulnerability affecting multiple Qualcomm chipsets. It can lead to memory corruption during graphics rendering that relies on Adreno GPU drivers in Chrome. For IT and security teams this matters because successful abuse of memory-corruption flaws in GPU drivers can undermine device integrity on platforms that use these chipsets, potentially allowing further compromise of the host environment. Specifics of impact and fixed releases must be confirmed against the vendor advisory.

How it works

The weakness is classified as CWE-416 (use-after-free). In this class of flaw, memory that has already been freed is later accessed again, creating an opportunity for corruption of adjacent memory structures. According to the available summary, the issue surfaces while rendering graphics with Adreno GPU drivers inside Chrome. An attacker who can influence the graphics content processed by the vulnerable driver path may trigger the use-after-free condition and achieve memory corruption. Exact trigger conditions, required privileges, and exploitation steps are not detailed in the public record and must be verified against the vendor advisory; defenders should treat any untrusted graphics content rendered through the affected path as a potential vector for this class of issue.

Am I affected? How to find it in your systems

Qualcomm chipsets appear in a wide range of mobile devices, embedded systems, and other platforms that incorporate Adreno GPUs. Inventory efforts should therefore focus on hardware that uses Qualcomm system-on-chip components and that runs Chrome or other software relying on the Adreno graphics stack.

How to remediate

The primary remediation is to apply the mitigations and updates supplied by the vendor for the affected chipsets and drivers. Follow the vendor instructions exactly; CISA guidance also directs organizations to apply those mitigations, to follow applicable BOD 22-01 guidance where cloud services are involved, or to discontinue use of the product if no mitigations are available.

If you can't patch immediately

When immediate patching is not feasible, reduce exposure with compensating controls while the update is prepared.

If your data may have been exposed

Actively exploited memory-corruption vulnerabilities can lead to device compromise and subsequent data exposure. Although ransomware use of this specific CVE is not documented, any confirmed exploitation should trigger standard incident-response procedures, including isolation of affected devices, forensic collection, and credential rotation. Organizations and individuals can also run a free exposure scan of their email addresses against known breach data sets to determine whether related accounts appear in previously disclosed incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQualcomm · Multiple Chipsets
WeaknessCWE-416
Added to CISA KEVJun 3, 2025
Federal patch deadlineJun 24, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities