PT-2025-23468 · Qualcomm · Qualcomm Snapdragon
Published
2025-01-24
·
Updated
2025-09-20
·
CVE-2025-21479
8.6
High
Base vector | Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
Qualcomm chipsets (affected versions not specified)
Meta Quest 3/3S versions August 7, 2025 and earlier
**Description:**
A memory corruption issue exists due to unauthorized command execution in the GPU micronode when processing a specific sequence of commands. This flaw has been actively exploited and affects multiple Qualcomm chipsets, including those found in the Meta Quest 3 and 3S devices. The vulnerability allows for potential memory corruption and unauthorized code execution. It is estimated that a large number of devices worldwide are affected. Exploitation of this issue has been observed in the wild, with reports indicating its use in attacks via the Adreno GPU. A proof-of-concept (PoC) exploit has been developed, enabling temporary root access on Meta Quest 3 and 3S devices.
**Recommendations:**
Qualcomm chipsets (affected versions not specified): At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Meta Quest 3/3S versions August 7, 2025 and earlier: Disable automatic updates and disconnect from Wi-Fi to prevent the installation of the patched firmware.
Exploit
RCE
LPE
Incorrect Authorization
Weakness Enumeration
Related Identifiers
Affected Products
References · 70
- 🔥 https://github.com/FreeXR/eureka_panther-adreno-gpu-exploit-1⭐ 2 · Exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-21479 · Security Note
- https://bdu.fstec.ru/vul/2025-06374 · Security Note
- https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html · Vendor Advisory
- https://twitter.com/CveFindCom/status/1929797757662847112 · Twitter Post
- https://twitter.com/xvonfers/status/1929531533087445253 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1l68nfr/top_10_trending_cves_08062025 · Reddit Post
- https://reddit.com/r/CVEWatch/comments/1mzmd82/top_10_trending_cves_25082025 · Reddit Post
- https://twitter.com/xvonfers/status/1952428886454579386 · Twitter Post
- https://t.me/latest_high_impact_cve/2527 · Telegram Post
- https://twitter.com/TweetThreatNews/status/1953035507581006192 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1mrqwf1/top_10_trending_cves_16082025 · Reddit Post
- https://twitter.com/grok/status/1956425860694839729 · Twitter Post
- https://reddit.com/r/SecOpsDaily/comments/1mlr01w/googles_august_patch_fixes_two_qualcomm · Reddit Post
- https://reddit.com/r/CVEWatch/comments/1l4ooat/top_10_trending_cves_06062025 · Reddit Post