CVE-2025-21479
Incorrect Authorization in Graphics
Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA notes
Please check with specific vendors (OEMs,) for information on patching status. For more information, please see: https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-21479
Description
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Severity
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| Qualcomm, Inc. | Snapdragon | AQT1000 FastConnect 6200 FastConnect 6700 FastConnect 6800 FastConnect 6900 FastConnect 7800 QCA6391 QCM4490 QCS4490 SD855 SM4635 SM6250 SM6650 SM6650P SM7325P SM7635 SM7675 SM7675P SM8550P SM8635 SM8635P SM8650Q Snapdragon 4 Gen 1 Mobile Platform Snapdragon 460 Mobile Platform Snapdragon 480 5G Mobile Platform Snapdragon 480+ 5G Mobile Platform (SM4350-AC) Snapdragon 662 Mobile Platform Snapdragon 680 4G Mobile Platform Snapdragon 685 4G Mobile Platform (SM6225-AD) Snapdragon 690 5G Mobile Platform Snapdragon 695 5G Mobile Platform Snapdragon 720G Mobile Platform Snapdragon 778G 5G Mobile Platform Snapdragon 778G+ 5G Mobile Platform (SM7325-AE) Snapdragon 782G Mobile Platform (SM7325-AF) Snapdragon 7c+ Gen 3 Compute Snapdragon 8 Gen 2 Mobile Platform Snapdragon 8 Gen 3 Mobile Platform Snapdragon 8+ Gen 2 Mobile Platform Snapdragon 855 Mobile Platform Snapdragon 855+/860 Mobile Platform (SM8150-AC) Snapdragon 865 5G Mobile Platform Snapdragon 865+ 5G Mobile Platform (SM8250-AB) Snapdragon 870 5G Mobile Platform (SM8250-AC) Snapdragon 888 5G Mobile Platform Snapdragon 888+ 5G Mobile Platform (SM8350-AC) Snapdragon AR1 Gen 1 Platform Snapdragon AR1 Gen 1 Platform "Luna1" Snapdragon X55 5G Modem-RF System SXR2230P SXR2250P SXR2330P WCD9341 WCD9370 WCD9375 WCD9378 WCD9380 WCD9385 WCD9390 WCD9395 WCN3950 WCN3988 WCN6450 WCN6650 WCN6755 WCN7861 WCN7881 WSA8810 WSA8815 WSA8830 WSA8832 WSA8835 WSA8840 WSA8845 WSA8845H |
References
1 LinksRecord Details
More from Qualcomm, Inc.
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.