Vulnerability record · CVE-2025-27038 · published 3 June 2025
CVE-2025-27038: Qualcomm Adreno GPU driver use-after-free in Chrome graphics rendering
Qualcomm · Ar8031 Firmware
A use-after-free (CWE-416) in Qualcomm Adreno GPU drivers causes memory corruption while rendering graphics in Chrome. It affects a broad set of Qualcomm chipsets and platforms, and CISA has added it to the Known Exploited Vulnerabilities catalog, so it is being exploited in the wild.
Description
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with known exploitation and high CVSS impact, though exploitation requires user interaction and high attack complexity.
What it is
A use-after-free (CWE-416) in Qualcomm Adreno GPU drivers causes memory corruption while rendering graphics in Chrome. It affects a broad set of Qualcomm chipsets and platforms, and CISA has added it to the Known Exploited Vulnerabilities catalog, so it is being exploited in the wild.
Impact
An attacker can corrupt memory in the GPU driver, which can lead to code execution or a crash in the affected context. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network (AV:N) but with high attack complexity (AC:H) and requiring user interaction (UI:R), consistent with a victim rendering attacker-influenced graphics content in Chrome. No privileges are required (PR:N).
Exploitation
CISA added it to KEV on 2025-06-03 with a 2025-06-24 remediation due date, indicating known exploitation; EPSS 30-day probability is low at 0.01016 (61.6th percentile). No ransomware campaign use is documented.
What to do
- Apply the Qualcomm June 2025 security bulletin fixes for the listed chipsets and platforms as the first action.
- Update Chrome and the underlying GPU driver to the latest vendor-supported versions on affected devices.
- Follow CISA BOD 22-01 guidance and the KEV required action; discontinue use of affected products if no mitigation is available.
- Track affected Qualcomm firmware products (for example sm6650, sm7635, qcm8550, fastconnect_7800) and confirm patched builds are deployed.
- Restrict or monitor untrusted graphics/web content on devices that cannot be patched promptly.
Detection
- Monitor for Chrome renderer or GPU process crashes consistent with memory corruption on affected Qualcomm devices.
- Hunt for abnormal GPU driver fault or use-after-free indicators in device crash and telemetry logs.
- Correlate exploitation attempts with KEV guidance and vendor bulletin advisories for the affected chipsets.
- Check endpoint inventories for unpatched Qualcomm firmware versions listed in the June 2025 bulletin.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-27038 to the Known Exploited Vulnerabilities catalog on 3 June 2025 as "Qualcomm Multiple Chipsets Use-After-Free Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 June 2025.
Affected products
44 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-27038 | US Government Resource |
Track CVE-2025-27038 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-27038), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.