Google’s August Patch Fixes Two Qualcomm Vulnerabilities Exploited in the Wild
Google发布安全更新修复Android系统中的多个漏洞,包括两个被标记为在野外被积极利用的高危Qualcomm漏洞(CVE-2025-21479和CVE-2025-27038),这些漏洞涉及图形组件可能导致内存损坏;CISA已将这些漏洞加入已知被利用目录,要求联邦机构尽快应用补丁;建议用户及时更新设备以防范威胁。 2025-8-5 13:59:0 Author: thehackernews.com(查看原文) 阅读量:42 收藏

Vulnerability / Mobile Security

Google has released security updates to address multiple security flaws in Android, including fixes for two Qualcomm bugs that were flagged as actively exploited in the wild.

The vulnerabilities include CVE-2025-21479 (CVSS score: 8.6) and CVE-2025-27038 (CVSS score: 7.5), both of which were disclosed alongside CVE-2025-21480 (CVSS score: 8.6), by the chipmaker back in June 2025.

CVE-2025-21479 relates to an incorrect authorization vulnerability in the Graphics component that could lead to memory corruption due to unauthorized command execution in GPU microcode.

CVE-2025-27038, on the other hand, use-after-free vulnerability in the Graphics component that could result in memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

There are still no details on how these shortcomings have been weaponized in real-world attacks, but Qualcomm noted at the time that "there are indications from Google Threat Analysis Group that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation."

Given that similar flaws in Qualcomm chipsets have been exploited by commercial spyware vendors like Variston and Cy4Gate in the past, it's suspected that the aforementioned shortcomings may also have been abused in a similar context.

Identity Security Risk Assessment

The three vulnerabilities have since been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the updates by June 24, 2025.

Google's August 2025 patch also resolves two high-severity privilege escalation flaws in Android Framework (CVE-2025-22441 and CVE-2025-48533) and a critical bug in the System component (CVE-2025-48530) that could result in remote code execution when combined with other flaws without requiring any additional privileges or user interaction.

The tech giant has made available two patch levels, 2025-08-01 and 2025-08-05, with the latter also incorporating fixes for closed-source and third-party components from Arm and Qualcomm. Android device users are advised to apply the updates as and when they become available to stay protected against potential threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2025/08/google-fixes-3-android-vulnerabilities.html
如有侵权请联系:admin#unsafe.sh