Skip to main content

CVE-2025-21480

8.6
HIGHCVSS v3.1 Base Score
2.00%
LOW RiskEPSS (84th percentile)
KEV

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

Published: 6/3/2025
Modified: 10/28/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Vendor / Product:

Qualcomm Multiple Chipsets

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Due Date: 6/24/2025(OVERDUE)
Added to KEV:

6/3/2025

Notes:

Please check with specific vendors (OEMs,) for information on patching status. For more information, please see: https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-21480

Vulnerability Summary

CVSS v3 Score

8.6HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

2.00%LOW Exploitation Risk
84th percentile

This vulnerability has a 2.00% probability of being exploited in the next 30 days, ranking higher than 84% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-863)

CVE-2025-66378MEDIUM 5.9

Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.

12/25/2025
CVE-2025-43336MEDIUM 4.4

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1, macOS Sonoma 14.8.2. An app with root privileges may be able to access private information.

11/4/2025
CVE-2025-55177MEDIUM 5.4

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

8/29/2025
CVE-2025-36157CRITICAL 9.8

IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to update server property files that would allow them to perform unauthorized actions.

8/24/2025
CVE-2025-55213CRITICAL 9.8

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm chart <= openfga-0.2.41, v1.9.3 <= docker <= v.1.9.4) are vulnerable to improper policy enforcement when certain Check and ListObject calls are executed. This vulnerability is fixed in 1.9.5.

8/18/2025

Similar SeverityHIGH