kevmap

Coverage › CVE-2025-21479

CVE-2025-21479 Mapped Mobile only

Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Vendor / product
Qualcomm — Multiple Chipsets
Description (CISA)
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
Added to KEV
2025-06-03
Due date
2025-06-24
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Known ransomware use
Unknown
CWE
CWE-863
CISA notes
Please check with specific vendors (OEMs,) for information on patching status. For more information, please see: https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html
https://nvd.nist.gov/vuln/detail/CVE-2025-21479
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28

2 mapping objects across 2 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such. Mappings marked mobile refer to ATT&CK Mobile; this site traverses the Enterprise bundle only and shows no detection chain for them.

TechniqueMapping typeCTID commentStatus in v19.2
T1631 Process Injectionmobile exploitation technique
ref 1 · ref 2
not checked (Mobile)
T1642 Endpoint Denial of Servicemobile primary impact
ref 1 · ref 2
not checked (Mobile)

Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources

No live Enterprise technique to traverse.