CVE-2025-21480
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CISA KEV
- Vendor
- Qualcomm
- Product
- Multiple Chipsets
- Due date
- 2025-06-24
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — Please check with specific vendors (OEMs,) for information on patching status. For more information, please see: https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-21480
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.