Qualcomm has released security updates addressing three zero-day vulnerabilities currently being exploited in limited, targeted attacks. These flaws, discovered and reported by Google’s Android Security team, affect the company’s Adreno Graphics Processing Unit (GPU) drivers.
## The Vulnerabilities
The critical security issues include:
– **CVE-2025-21479 and CVE-2025-21480** (CVSS score: 8.6): Two incorrect authorization vulnerabilities in the Graphics component that could lead to memory corruption through unauthorized command execution in GPU microcode.
– **CVE-2025-27038** (CVSS score: 7.5): A use-after-free vulnerability in the Graphics component potentially causing memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
According to Qualcomm’s advisory, “There are indications from Google Threat Analysis Group that these vulnerabilities may be under limited, targeted exploitation.” The company has distributed patches to device manufacturers in May with “a strong recommendation to deploy the update on affected devices as soon as possible.”
## Historical Context
While details about current exploitation methods remain undisclosed, similar Qualcomm chipset vulnerabilities have previously been weaponized by commercial spyware vendors like Variston and Cy4Gate.
In December, Amnesty International reported that another Qualcomm security flaw (CVE-2024-43047) was exploited by Serbian security agencies to unlock seized Android devices belonging to activists, journalists, and protesters, using Cellebrite’s data extraction software to deploy spyware called NoviSpy.
