Skip to content
COOEY

EXPOSURES › CVE-2025-21480

CVE-2025-21480

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-06-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-21480 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Qualcomm chipsets exploited for unauthorized command execution

Multiple Qualcomm chipsets allowed unauthorized command execution in GPU micronode, leading to memory corruption. This was actively exploited in the wild, posing a high risk to DIB organizations using these products.

Shame score — Active exploitation in the wild indicates negligence in security practices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.