7.5

CVE-2025-27038

Warning

Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

Data is provided by the National Vulnerability Database (NVD)
QualcommAr8031 Firmware Version-
   QualcommAr8031 Version-
QualcommCsra6620 Firmware Version-
   QualcommCsra6620 Version-
QualcommCsra6640 Firmware Version-
   QualcommCsra6640 Version-
QualcommQca2066 Firmware Version-
   QualcommQca2066 Version-
QualcommQca6391 Firmware Version-
   QualcommQca6391 Version-
QualcommQcm6125 Firmware Version-
   QualcommQcm6125 Version-
QualcommQcm8550 Firmware Version-
   QualcommQcm8550 Version-
QualcommQcn9011 Firmware Version-
   QualcommQcn9011 Version-
QualcommQcn9012 Firmware Version-
   QualcommQcn9012 Version-
QualcommQcs6125 Firmware Version-
   QualcommQcs6125 Version-
QualcommQcs8550 Firmware Version-
   QualcommQcs8550 Version-
QualcommSm6475 Firmware Version-
   QualcommSm6475 Version-
QualcommSm6650 Firmware Version-
   QualcommSm6650 Version-
QualcommSm6650p Firmware Version-
   QualcommSm6650p Version-
QualcommSm7435 Firmware Version-
   QualcommSm7435 Version-
QualcommSm7635 Firmware Version-
   QualcommSm7635 Version-
QualcommSm7635p Firmware Version-
   QualcommSm7635p Version-
QualcommSw5100 Firmware Version-
   QualcommSw5100 Version-
QualcommSw5100p Firmware Version-
   QualcommSw5100p Version-
QualcommWcd9335 Firmware Version-
   QualcommWcd9335 Version-
QualcommWcd9370 Firmware Version-
   QualcommWcd9370 Version-
QualcommWcd9375 Firmware Version-
   QualcommWcd9375 Version-
QualcommWcd9378 Firmware Version-
   QualcommWcd9378 Version-
QualcommWcd9385 Firmware Version-
   QualcommWcd9385 Version-
QualcommWcd9395 Firmware Version-
   QualcommWcd9395 Version-
QualcommWcn3950 Firmware Version-
   QualcommWcn3950 Version-
QualcommWcn3980 Firmware Version-
   QualcommWcn3980 Version-
QualcommWcn3988 Firmware Version-
   QualcommWcn3988 Version-
QualcommWcn6650 Firmware Version-
   QualcommWcn6650 Version-
QualcommWcn6740 Firmware Version-
   QualcommWcn6740 Version-
QualcommWcn6755 Firmware Version-
   QualcommWcn6755 Version-
QualcommWsa8810 Firmware Version-
   QualcommWsa8810 Version-
QualcommWsa8815 Firmware Version-
   QualcommWsa8815 Version-
QualcommWsa8830 Firmware Version-
   QualcommWsa8830 Version-
QualcommWsa8832 Firmware Version-
   QualcommWsa8832 Version-
QualcommWsa8835 Firmware Version-
   QualcommWsa8835 Version-

03.06.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Vulnerability

Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

Description

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.81% 0.822
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
product-security@qualcomm.com 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.