Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Qualcomm Adreno GPU Memory Corruption Vulnerability Allowing Unauthorized Command Execution

Vulnerability

A memory corruption vulnerability has been identified in the Adreno Graphics Processing Unit (GPU) driver, specifically within the GPU micronode. This issue arises from unauthorized command execution, which leads to memory corruption while the GPU is processing certain sequences of commands. The vulnerability is present in various chipsets, including several Snapdragon mobile platforms, and has been reported to Qualcomm on January 24, 2025.

Impact

Exploitation of this vulnerability causes memory corruption, which can lead to use-after-free conditions, allowing for potential arbitrary code execution. This vulnerability is part of a broader set of vulnerabilities in the Adreno GPU driver that have been reported to be under limited, targeted exploitation.

Remediation

Qualcomm has patched this vulnerability and shared the update with device manufacturers. Instructions for applying the patch can be obtained from the device manufacturer.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
6.4
remediation
7.7
relevance
0.1
threat
8.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.