LiveActive security incident?Get immediate response
CVE Record

CVE-2025-21480: Incorrect Authorization in Graphics Windows

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

HighCVSS 8.6Known exploitedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2025-21480 is a high-severity Qualcomm Snapdragon graphics/GPU vulnerability. It can corrupt memory when unauthorized GPU micronode commands are executed in a specific sequence. CISA lists it in KEV, so organizations should treat affected Snapdragon-based devices as an active-risk population.

Executive priority

Treat this as a priority mobile and endpoint firmware issue, not a routine software bug. KEV status means exploitation is known, while the broad affected platform list raises asset-identification risk across phones, laptops, embedded devices, and wireless components.

Technical view

The issue is CWE-863 incorrect authorization leading to memory corruption in Snapdragon graphics/GPU handling. CVSS 3.1 is 8.6 with local access, low complexity, no privileges, required user interaction, changed scope, and high confidentiality, integrity, and availability impact.

Likely exposure

Exposure is tied to devices using the listed Qualcomm Snapdragon and related components, including many mobile, compute, modem, Wi-Fi, and audio platforms. The bundle does not identify specific phone, laptop, or OEM device models.

Exploitation context

Active exploitation is supported by the CISA Known Exploited Vulnerabilities listing for CVE-2025-21480. The provided CVSS vector indicates local attack conditions and user interaction, but the source bundle does not provide exploit mechanics or observed campaign details.

Researcher notes

The bundle identifies authorization failure and memory corruption in GPU micronode command handling, but lacks patch identifiers, affected OEM models, exploit detail, or forensic indicators. Researchers should focus on platform mapping, vendor bulletin correlation, and safe validation of update status.

Mitigation direction

  • Inventory assets for the affected Qualcomm Snapdragon platforms listed in the CVE record.
  • Review Qualcomm’s June 2025 bulletin and OEM advisories for applicable update guidance.
  • Apply vendor or OEM updates where guidance confirms coverage for your platform.
  • Prioritize managed assets because CISA KEV indicates known exploitation.
  • Limit installation of untrusted local apps until vendor guidance is applied.

Validation and detection

  • Map device hardware identifiers to Qualcomm platforms named in the CVE record.
  • Compare device firmware and security patch status against Qualcomm and OEM advisories.
  • Check CISA KEV for the current listing and remediation expectations.
  • Verify update deployment through MDM, endpoint inventory, or OEM management tooling.
  • Review crash and security telemetry for unusual graphics/GPU driver instability.
Prepared
Confidence
high
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-863: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-21480 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.6 (3.1)
Known Exploited
Yes
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CISA KEV status

Status
Known exploited
Source
CISA / ADP
Date added
Not provided

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.6CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H1.86Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

8.6High
CVSS 3.1 vector shape for CVE-2025-21480Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Qualcomm, Inc.SnapdragonAQT1000, FastConnect 6200, FastConnect 6700, FastConnect 6800, FastConnect 6900, FastConnect 7800, QCA6391, QCM4490, QCS4490, SC8380XP, SD855, SM4635, SM6250, SM6650, SM6650P, SM7325P, SM7635, SM7675, SM7675P, SM8550P, SM8635, SM8635P, SM8650Q, Snapdragon 4 Gen 1 Mobile Platform, Snapdragon 460 Mobile Platform, Snapdragon 480 5G Mobile Platform, Snapdragon 480+ 5G Mobile Platform (SM4350-AC), Snapdragon 662 Mobile Platform, Snapdragon 680 4G Mobile Platform, Snapdragon 685 4G Mobile Platform (SM6225-AD), Snapdragon 690 5G Mobile Platform, Snapdragon 695 5G Mobile Platform, Snapdragon 720G Mobile Platform, Snapdragon 778G 5G Mobile Platform, Snapdragon 778G+ 5G Mobile Platform (SM7325-AE), Snapdragon 782G Mobile Platform (SM7325-AF), Snapdragon 7c+ Gen 3 Compute, Snapdragon 8 Gen 2 Mobile Platform, Snapdragon 8 Gen 3 Mobile Platform, Snapdragon 8+ Gen 2 Mobile Platform, Snapdragon 855 Mobile Platform, Snapdragon 855+/860 Mobile Platform (SM8150-AC), Snapdragon 865 5G Mobile Platform, Snapdragon 865+ 5G Mobile Platform (SM8250-AB), Snapdragon 870 5G Mobile Platform (SM8250-AC), Snapdragon 888 5G Mobile Platform, Snapdragon 888+ 5G Mobile Platform (SM8350-AC), Snapdragon AR1 Gen 1 Platform, Snapdragon AR1 Gen 1 Platform "Luna1", Snapdragon X55 5G Modem-RF System, SXR2230P, SXR2250P, SXR2330P, WCD9341, WCD9370, WCD9375, WCD9378, WCD9380, WCD9385, WCD9390, WCD9395, WCN3950, WCN3988, WCN6450, WCN6650, WCN6755, WCN7861, WCN7881, WSA8810, WSA8815, WSA8830, WSA8832, WSA8835, WSA8840, WSA8845, WSA8845Hunaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-863 · source CWE mapping

Incorrect Authorization

Incorrect Authorization represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.