Qualcomm has patched three Adreno GPU zero-day vulnerabilities (CVE-2025-21479, CVE-2025-21480, CVE-2025-27038) that were being exploited in the wild since January 2025.
Google Threat Analysis Group hints at limited, targeted exploitation of the vulnerabilities.
Qualcomm has provided the patches to OEMs with a strong recommendation to deploy them on affected devices as soon as possible.
No specific details on the attackers using the vulnerabilities have been disclosed, but similar flaws have been utilized in spyware campaigns in the past.