Breaking
June 5, 2025

Qualcomm finally patches Adreno GPU zero-day flaws used in Android attacks | usagoldmines.com


  • Qualcomm has addressed three zero-days abused since January 2025
  • The patches must now be applied by OEMs
  • No details about in-the-wild abuse, but users should still be on guard

Qualcomm has finally patched three Adreno GPU zero-day vulnerabilities that were being abused in the wild.

According to the June 2025 Android Security Bulletin, the chipmaker has now fixed CVE-2025-21479, CVE-2025-21480, and CVE-2025-27038.

The first two are incorrect authorization flaws in the Graphics component. They were given a severity score of 8.6/10 (high), and could trigger memory corruption. They were first observed in January 2025. The third bug is a use-after-free vulnerability in the Graphics component that also leads to memory corruption. This one was given a lower severity score – 7.5/10.

Payment information intact

“There are indications from Google Threat Analysis Group that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation,” Qualcomm explained.

“Patches for the issues affecting the Adreno Graphics Processing Unit (GPU) driver have been made available to OEMs in May together with a strong recommendation to deploy the update on affected devices as soon as possible.”

Now, it’s up to different device manufacturers, such as Samsung, Google OnePlus, or Xiaomi, to apply these patches in their products.

The affected devices span a wide range of Qualcomm chipsets, including flagship models like the Snapdragon 8 Gen 2 and Gen 3, as well as midrange and budget platforms such as the Snapdragon 695, 778G, and 4 Gen 1/2.

There are currently no details on who abused these flaws, against whom, and to what end, however similar vulnerabilities were seen used in the past in spyware campaigns such as Variston and Cy4Gate.

A separate Qualcomm bug (CVE-2024-43047) was used by Serbian secret service agency, BIA, in December 2024, to unlock Android devices seized from journalists, activists, and protestors, the same source claims.

Via The Hacker News

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

iPhone 17 May Support Up to 50W MagSafe Wireless Charging (Qi 2.2) Tim Hardwick | usagoldmines.com

The first trailer for 007 First Light reveals a young James Bond and it's coming to PC and console i...

The Google Pixel 10 series colors have leaked in full – and two old favorites are missing | usagold...

Microsoft launches free cybersecurity protection for European governments against AI threats and mor...

How AI can help experts protect their mental health | usagoldmines.com

The Samsung Galaxy Z Fold 7 could have a huge screen with tiny bezels | usagoldmines.com

Exclusive 28 Years Later character video teases bone-chilling new details about Ralph Fiennes' Docto...

Fake IT support voice calls lead to cyber extortion and stolen company data | usagoldmines.com

I haven’t seen ads in years thanks to this hack | usagoldmines.com

The best small wireless stereo speakers just got upgraded with better sound in the same great-lookin...

Beyond AI-powered cybersecurity: why context and visibility are still a CISO’s top priority | usago...

WWDC 2025: New Features We Could See in watchOS 26 Juli Clover | usagoldmines.com

Malware affiliate pyramid scheme is shuttered by US feds: here's how to keep safe | usagoldmines.co...

The Nintendo Switch 2 launch mania makes me miss the early iPhone launch days lance.ulanoff@futurene...

One of world's largest oil companies just launched a unique cooling fluid for data centers and AI ch...

Best PC computer deals: Top picks from desktops to all-in-ones | usagoldmines.com

Android 16 QPR1 Beta 1.1 Released for Pixel Devices Tim | usagoldmines.com

How Old Is Too Old When Buying an Apple Watch? Lindsey Ellefson | usagoldmines.com

Court Rejects Apple's Emergency Motion to Pause App Store Rule Changes Juli Clover | usagoldmines.co...

US science is being wrecked, and its leadership is fighting the last war John Timmer | usagoldmines....

New filament lets you 3D-print parts in authentic 1980s Apple computer color Benj Edwards | usagoldm...

Samsung Slaps $1,000 Off Galaxy Z Fold 6 Kellen | usagoldmines.com

How to Reset Your Nintendo Switch Before You Sell It Eric Ravenscraft | usagoldmines.com

Meta Apps Have Been Covertly Tracking Android Users' Web Activity for Months Jake Peterson | usagold...

Google plans to get its AI to write your emails for you erichs211@gmail.com (Eric Hal Schwartz) | us...

FCC Republican resigns, leaving agency with just two commissioners Jon Brodkin | usagoldmines.com

Jared Isaacman speaks out, and it’s clear that NASA lost a visionary leader Eric Berger | usagoldmin...

Pixel 10 Color Confusion Arrives Because, Why Not? Kellen | usagoldmines.com

Colors and Storage Options for Samung’s Upcoming Foldable Lineup Revealed Tim | usagoldmines.com

You Can Now Curate Your Public Reddit Profile Emily Long | usagoldmines.com

The Nothing Phone 3 Has a Launch Date, but I'm Not Sure the Price Is Right Jake Peterson | usagoldmi...

GhatGPT Can Now Remember Conversations for Free Users Too Khamosh Pathak | usagoldmines.com

iOS 26 Could Bring Sleep Detection, Camera Controls, and New Gestures to AirPods Juli Clover | usago...

Ready, set, gone: why popups, freezing, and tiny text are causing millions of app users to jump ship...

Remember The Simpsons Funday Football tie-in? Sony’s new NHL deal could see more animated heroes on ...

A new 'Wikipedia for extensions' wants to make your web browser far more secure by exposing dangerou...

American Science & Surplus is fighting for its life. Here’s why you should care. Eric Bangeman |...

OpenAI slams court order to save all ChatGPT logs, including deleted chats Ashley Belanger | usagold...

Samsung's ‘Goldilocks’ Galaxy phone may have set the standard for Apple’s iPhone 17 Air to chase | ...

Meta basically just bought a nuclear power plant | usagoldmines.com

If you haven't considered this super high-end bed with inbuilt KEF speakers, do you even love music?...

Lawsuit: DOGE, HHS used “hopelessly error-ridden” data to fire 10,000 workers Jon Brodkin | usagoldm...

It’s here: Unboxing and setting up our Switch 2 review unit Kyle Orland | usagoldmines.com

Alienware gets bricked (in a good way) with custom Lego set | usagoldmines.com

How to Watch Pornhub Even If It's Blocked In Your State David Nield | usagoldmines.com

Android Users Will Finally Be Able to Sync Their Garmin Fitness Data Meredith Dietz | usagoldmines.c...

Watch Out for Fake Websites Posing As Booking.com Emily Long | usagoldmines.com

How to Protect Your Car From Identity Theft Jeff Somers | usagoldmines.com

Cybercriminals are using SEO to get popular fake AI tools loaded with malware to rank high on Google...

Disney+ confirms release date for the Rachel Zegler led Snow White movie after its disappointing box...

Review: At $349, AMD’s 16GB Radeon RX 9060 XT is the new midrange GPU to beat Andrew Cunningham | us...

Are Dead Sea Scrolls older than we thought? Jennifer Ouellette | usagoldmines.com

The best gaming monitors: 9 displays that will do your games justice | usagoldmines.com

Tapo C410 Kit review: Home security powered by the sun | usagoldmines.com

Google Paused Rollout of Its “Ask Photos” AI Search in Google Photos Kellen | usagoldmines.com

I Tried Bing’s Free AI Video Generator, and It’s No Match for the Paid Options Khamosh Pathak | usag...

Samsung Will Soon Delete Your Inactive Account Unless You Log In Jake Peterson | usagoldmines.com

iOS 18.6 Apple Intelligence Launch in China Delayed by U.S.-China Trade Tensions Juli Clover | usago...

Max’s Mountainhead is the new tech bro satire from the creator of Succession, starring Steve Carrell...

Tesla shows no sign of improvement in May sales data Jonathan M. Gitlin | usagoldmines.com

Don’t toss your Windows 10 PC! Try switching to Plasma instead | usagoldmines.com

The best free VPNs: 5 no-cost top picks | usagoldmines.com

Five Shows to Watch While You Wait for 'Severance' Season 3 Stephen Johnson | usagoldmines.com

"DNS resolvers aren’t a censorship tool" – experts warn against the risks of growing internet blocki...

I've used iPads for 10 years – here are the iPadOS 19 features I want to see from WWDC jamie.richard...

No Man's Sky will launch on the Nintendo Switch 2 with full multiplayer, including cross-save and cr...

Philips Hue is launching a stylish new smart light to 'wash' your walls with color – early Amazon li...

Google quietly released a security fix for a worrying Chrome zero-day flaw, so patch now | usagoldm...

Samsung teams up with Glance to use your face in AI-generated lock screen ads Ryan Whitwam | usagold...

MSI’s Cyclone RTX GPUs are really back, starting with the RTX 5060 | usagoldmines.com

This fast Anker charging station fits 9 devices at once for only $36 | usagoldmines.com

Mozilla begins screening Firefox extensions for crypto scams | usagoldmines.com

Galaxy Watch 5 Lineup, Watch Ultra Get Security Patch Updates Tim | usagoldmines.com

This Site Brings Me Back to the Glory Days of 'Local on the 8s' Weather Channel Forecasts Justin Pot...

This Malware Adds a ‘Trusted’ Contact to Your Android Phone Emily Long | usagoldmines.com

Will iOS 26 Be Compatible With Your iPhone? Here's the Rumored List Joe Rossignol | usagoldmines.com

Make Live Photos Loop, Bounce, and More on iPhone Tim Hardwick | usagoldmines.com

Will Apple Preview Its Rumored 'HomePad' at WWDC Next Week? Joe Rossignol | usagoldmines.com

Spotify admits it made mistakes with your Wrapped 2024 – here's what could change this year rowan.da...

I'm excited about the Galaxy Z Fold 7 Ultra's possible new cameras, but what I want is an integrated...

DJI says it ‘welcomes’ imminent US drone ban review – here’s why | usagoldmines.com

Public DevOps tools targeted by criminals to steal crypto | usagoldmines.com

New The Fantastic Four: First Steps trailer confirms two of the worst-kept secrets about the Marvel ...

Nvidia has a new GeForce hotfix GPU driver to address several issues – but I'm terrified of installi...

LG’s super-fast 480Hz 1440p OLED gaming monitor is $250 off | usagoldmines.com

Why use a good password? Here’s what you stand to lose | usagoldmines.com

This High Resolution, 360-Degree Camera Is $140 Off Right Now Pradershika Sharma | usagoldmines.com

Anker Father's Day Sale Introduces Big Discounts on MagSafe-Compatible Chargers and More Mitchel Bro...

Nintendo Switch 2’s launch titles are awesome, but this one free update means more to me than any ne...

Can’t wait for AMD’s next-gen Ryzen CPUs? Zen 6 sighting hints they could arrive late in 2026, possi...

NYT Connections hints and answers for Thursday, June 5 (game #725) | usagoldmines.com

NYT Strands hints and answers for Thursday, June 5 (game #459) | usagoldmines.com

Quordle hints and answers for Thursday, June 5 (game #1228) | usagoldmines.com

PlayStation State of Play build-up live: today's June presentation is just hours away rob.dwiar@futu...

'We just focused on this story': Ballerina director explains why it doesn't set up the next outing f...

Time is money - and a cyber risk problem | usagoldmines.com

AI in B2B ecommerce: from optional to essential | usagoldmines.com

An in-space propulsion company just raised a staggering amount of money Eric Berger | usagoldmines.c...

Science PhDs face a challenging and uncertain future Claudia López Llareda, Undark Magazine | usagol...

Top CDC COVID vaccine expert resigns after RFK Jr. unilaterally restricts access Beth Mole | usagold...