CVE-2025-27038: Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Published Jun 3, 2025
·Updated
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
Affected Software
91 affected components
Google Chrome
Qualcomm Multiple Chipsets
All of the following
Qualcomm Ar8031 Firmware
Qualcomm Ar8031
All of the following
Qualcomm Csra6620 Firmware
Qualcomm Csra6620
All of the following
Qualcomm Csra6640 Firmware
Qualcomm Csra6640
All of the following
Qualcomm Fastconnect 7800 Firmware
Qualcomm Fastconnect 7800
All of the following
Qualcomm Qca2066 Firmware
Qualcomm Qca2066
All of the following
Qualcomm Qca6391 Firmware
Qualcomm Qca6391
All of the following
Qualcomm Qcm6125 Firmware
Qualcomm Qcm6125
All of the following
Qualcomm Qcm8550 Firmware
Qualcomm Qcm8550
All of the following
Qualcomm Qcn9011 Firmware
Qualcomm Qcn9011
All of the following
Qualcomm Qcn9012 Firmware
Qualcomm Qcn9012
All of the following
Qualcomm Qcs6125 Firmware
Qualcomm Qcs6125
All of the following
Qualcomm Qcs8550 Firmware
Qualcomm Qcs8550
All of the following
Qualcomm Video Collaboration Vc1 Platform Firmware
Qualcomm Video Collaboration Vc1 Platform
All of the following
Qualcomm Sm6475 Firmware
Qualcomm Sm6475
All of the following
Qualcomm Sm6650 Firmware
Qualcomm Sm6650
All of the following
Qualcomm Sm6650p Firmware
Qualcomm Sm6650p
All of the following
Qualcomm Sm7435 Firmware
Qualcomm Sm7435
All of the following
Qualcomm Sm7635 Firmware
Qualcomm Sm7635
All of the following
Qualcomm Sm7635p Firmware
Qualcomm Sm7635p
All of the following
Qualcomm Smart Audio 400 Platform Firmware
Qualcomm Smart Audio 400 Platform
All of the following
Qualcomm Snapdragon 4 Gen 2 Mobile Platform Firmware
Qualcomm Snapdragon 4 Gen 2 Mobile Platform
All of the following
Qualcomm Snapdragon 6 Gen 1 Mobile Platform Firmware
Qualcomm Snapdragon 6 Gen 1 Mobile Platform
All of the following
Qualcomm Snapdragon 680 4g Mobile Platform Firmware
Qualcomm Snapdragon 680 4g Mobile Platform
All of the following
Qualcomm Snapdragon 685 4g Mobile Platform \(sm6225-ad\) Firmware
Qualcomm Snapdragon 685 4g Mobile Platform \(sm6225-ad\)
All of the following
Qualcomm Snapdragon W5\+ Gen 1 Wearable Platform Firmware
Qualcomm Snapdragon W5\+ Gen 1 Wearable Platform
All of the following
Qualcomm Sw5100 Firmware
Qualcomm Sw5100
All of the following
Qualcomm Sw5100p Firmware
Qualcomm Sw5100p
All of the following
Qualcomm Wcd9335 Firmware
Qualcomm Wcd9335
All of the following
Qualcomm Wcd9370 Firmware
Qualcomm Wcd9370
All of the following
Qualcomm Wcd9375 Firmware
Qualcomm Wcd9375
All of the following
Qualcomm Wcd9378 Firmware
Qualcomm Wcd9378
All of the following
Qualcomm Wcd9385 Firmware
Qualcomm Wcd9385
All of the following
Qualcomm Wcd9395 Firmware
Qualcomm Wcd9395
All of the following
Qualcomm Wcn3950 Firmware
Qualcomm Wcn3950
All of the following
Qualcomm Wcn3980 Firmware
Qualcomm Wcn3980
All of the following
Qualcomm Wcn3988 Firmware
Qualcomm Wcn3988
All of the following
Qualcomm Wcn6650 Firmware
Qualcomm Wcn6650
All of the following
Qualcomm Wcn6740 Firmware
Qualcomm Wcn6740
All of the following
Qualcomm Wcn6755 Firmware
Qualcomm Wcn6755
All of the following
Qualcomm Wsa8810 Firmware
Qualcomm Wsa8810
All of the following
Qualcomm Wsa8815 Firmware
Qualcomm Wsa8815
All of the following
Qualcomm Wsa8830 Firmware
Qualcomm Wsa8830
All of the following
Qualcomm Wsa8832 Firmware
Qualcomm Wsa8832
All of the following
Qualcomm Wsa8835 Firmware
Qualcomm Wsa8835
Google Android
Remediation
Information
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Event History
Aug 14, 2024
News Published
12:45 AM
Jun 2, 2025
News Published
via BleepingComputer·11:11 AM
News Published
via BleepingComputer·11:12 AM
Jun 3, 2025
CVE Published
via CISA·12:00 AM
Known Exploited
via CISA·12:00 AM
CVE Published
via MITRE·05:53 AM
Data Sourced
via MITRE·05:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Jun 4, 2025
News Published
via ZDNet·04:24 PM
News Published
via ZDNet·04:41 PM
Aug 4, 2025
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Aug 5, 2025
News Published
via BleepingComputer·10:31 AM
Aug 12, 2025
News Published
via The Register·11:34 PM
News Published
via The Register·11:38 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-27038?
CVE-2025-27038 is rated as a high-severity vulnerability due to potential exploits that can lead to memory corruption.
2
How do I fix CVE-2025-27038?
To mitigate CVE-2025-27038, ensure that you update to the latest version of Google Chrome as soon as an update is available.
3
What causes the vulnerability CVE-2025-27038?
CVE-2025-27038 is caused by memory corruption during graphic rendering using Adreno GPU drivers in the Chrome browser.
4
Is CVE-2025-27038 being actively exploited?
Yes, CVE-2025-27038 has been reported to be exploited in the wild, which emphasizes the importance of updating software promptly.
5
Who is affected by CVE-2025-27038?
Users of Google Chrome that utilize devices with Adreno GPU drivers are affected by CVE-2025-27038.