Article Details
Scrape Timestamp (UTC): 2025-06-02 14:22:37.338
Source: https://thehackernews.com/2025/06/qualcomm-fixes-3-zero-days-used-in.html
Original Article Text
Click to Toggle View
Qualcomm Fixes 3 Zero-Days Used in Targeted Android Attacks via Adreno GPU. Qualcomm has shipped security updates to address three zero-day vulnerabilities that it said have been exploited in limited, targeted attacks in the wild. The flaws in question, which were responsibly disclosed to the company by the Google Android Security team, are listed below - "There are indications from Google Threat Analysis Group that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation," Qualcomm said in an advisory. "Patches for the issues affecting the Adreno Graphics Processing Unit (GPU) driver have been made available to OEMs in May together with a strong recommendation to deploy the update on affected devices as soon as possible." There are currently no details on how the vulnerabilities are being exploited, in what context, and by whom. That said, similar flaws in Qualcomm chipsets (CVE-2023-33063, CVE-2023-33106, and CVE-2023-33107) have been weaponized in the past by purveyors of commercial spyware like Variston and Cy4Gate. Last December, Amnesty International revealed that another security flaw in Qualcomm (CVE-2024-43047) had been exploited by the Serbian Security Information Agency (BIA) and the Serbian police to unlock seized Android devices belonging to activists, journalists, and protestors using Cellebrite's data extraction software to gain elevated access and deploy an Android spyware called NoviSpy.
Daily Brief Summary
Qualcomm has released updates to fix three zero-day vulnerabilities in its Adreno GPU, exploited in targeted attacks.
The vulnerabilities were responsibly reported by the Google Android Security team and confirmed by indications from Google Threat Analysis Group.
The specific vulnerabilities, labeled CVE-2025-21479, CVE-2025-21480, and CVE-2025-27038, were exploited in limited, selective scenarios.
Patches for the affected GPU drivers were distributed to Original Equipment Manufacturers (OEMs) with an urgent recommendation to update devices immediately.
Previous similar vulnerabilities in Qualcomm chipsets have been used by commercial spyware providers like Variston and Cy4Gate.
In a related incident, a security flaw identified as CVE-2024-43047 was used by Serbian authorities to access and spy on Android devices owned by activists and journalists.
The exact methods of exploitation and the attackers behind these current vulnerabilities remain undisclosed.