Executive brief
A security vulnerability exists in several Qualcomm chipsets used in mobile devices and connectivity hardware. This flaw allows unauthorized commands to be executed on the Graphics Processing Unit (GPU), which can lead to memory corruption and potential system takeover. This vulnerability has been observed being used in real-world attacks, making it a high priority for patching to protect user data and device integrity.
Technical details
This vulnerability is classified as an Incorrect Authorization (CWE-863) issue within the GPU micronode of multiple Qualcomm chipsets. It is triggered when a specific sequence of commands is executed, allowing for unauthorized command execution that results in memory corruption. The attack vector is local, requiring user interaction (UI:R) but potentially leading to a scope change (S:C) with high impact on confidentiality, integrity, and availability. This flaw is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation. Patches are available via Qualcomm's June 2025 security bulletin.
Affected products
- Qualcomm Multiple Chipsets Firmware Multiple chipsets including SD855, FastConnect 6200/6700/6800/6900/7800, QCM4490, QCS4490, and others
Timeline
- 2025-06-03: advisory: Qualcomm published the security bulletin and NVD entry was created.
- 2025-06-03: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog.
- 2025-06-03: exploited: Vulnerability reported as exploited in the wild.