CVE-2025-27038
Use After Free in Graphics
Qualcomm Multiple Chipsets Use-After-Free Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA notes
Please check with specific vendors (OEMs,) for information on patching status. For more information, please see: https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-27038
Description
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| Qualcomm, Inc. | Snapdragon | AR8031 CSRA6620 CSRA6640 FastConnect 7800 QCA2066 QCA6391 QCM6125 QCM8550 QCN9011 QCN9012 QCS6125 QCS8550 Qualcommr Video Collaboration VC1 Platform SM6475 SM6650 SM6650P SM7435 SM7635 SM7635P Smart Audio 400 Platform Snapdragon 4 Gen 2 Mobile Platform Snapdragon 6 Gen 1 Mobile Platform Snapdragon 680 4G Mobile Platform Snapdragon 685 4G Mobile Platform (SM6225-AD) Snapdragon W5+ Gen 1 Wearable Platform SW5100 SW5100P WCD9335 WCD9370 WCD9375 WCD9378 WCD9385 WCD9395 WCN3950 WCN3980 WCN3988 WCN6650 WCN6740 WCN6755 WSA8810 WSA8815 WSA8830 WSA8832 WSA8835 |
References
1 LinksRecord Details
More from Qualcomm, Inc.
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.