Coverage › CVE-2025-21479
CVE-2025-21479 Mapped Mobile only
Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
- Vendor / product
- Qualcomm — Multiple Chipsets
- Description (CISA)
- Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
- Added to KEV
- 2025-06-03
- Due date
- 2025-06-24
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known ransomware use
- Unknown
- CWE
- CWE-863
- CISA notes
- Please check with specific vendors (OEMs,) for information on patching status. For more information, please see: https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html
https://nvd.nist.gov/vuln/detail/CVE-2025-21479 - Elsewhere
- cve.org · NVD · CISA KEV · JSON
ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28
2 mapping objects across 2 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such. Mappings marked mobile refer to ATT&CK Mobile; this site traverses the Enterprise bundle only and shows no detection chain for them.
| Technique | Mapping type | CTID comment | Status in v19.2 |
|---|---|---|---|
| T1631 Process Injectionmobile | exploitation technique | — ref 1 · ref 2 |
not checked (Mobile) |
| T1642 Endpoint Denial of Servicemobile | primary impact | — ref 1 · ref 2 |
not checked (Mobile) |
Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources
No live Enterprise technique to traverse.