frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Google Android Team Finds Critical Qualcomm GPU Flaws Affecting Millions

2•Great_Cat•10h ago
Google’s Android Security team, notably the Threat Analysis Group (TAG), has recently disclosed multiple critical zero-day vulnerabilities affecting Qualcomm’s Adreno GPU drivers — components embedded in the graphics subsystem of billions of Android devices worldwide. These vulnerabilities have been actively exploited in the wild, representing a severe security risk to end users.

Technical Overview

The flaws, identified as CVE-2025-21479, CVE-2025-21480, and CVE-2025-27038, are primarily rooted in memory corruption issues and improper authorization checks within the GPU’s driver code. Due to the Adreno GPU’s privileged position in the Android kernel space, these bugs enable attackers to escalate privileges from user space to kernel space by crafting malicious GPU command streams or malformed graphics data. • CVE-2025-21479 & CVE-2025-21480: These vulnerabilities relate to incorrect authorization mechanisms in the command execution path of the Adreno GPU driver. An attacker controlling a malicious app or injected code can bypass standard access controls, leading to unauthorized command execution within the GPU microkernel, which can corrupt memory or trigger out-of-bounds writes. • CVE-2025-27038: This is a use-after-free vulnerability that occurs during the rendering pipeline. When exploited, it can cause arbitrary code execution by manipulating freed memory buffers, enabling attackers to run arbitrary code with kernel-level privileges.

Impact and Exploitation

The Qualcomm Adreno GPU driver is widely deployed across Snapdragon chipsets powering numerous flagship and mid-range devices from manufacturers such as Samsung, OnePlus, Xiaomi, and more. Because these GPUs interact closely with the Android kernel, exploitation of these vulnerabilities enables: • Remote Code Execution (RCE): Attackers can execute arbitrary code on the device remotely without requiring user interaction in some scenarios. • Privilege Escalation: Gaining kernel privileges, thereby bypassing Android’s security sandboxing and app permission models. • Persistent Malware Installation: Ability to install rootkits or persistent malware modules that survive device reboots. • Data Exfiltration and Surveillance: Unauthorized access to sensitive user data, including credentials, messages, and media files.

Google TAG’s reports confirmed active exploitation of these zero-day flaws, underlining the urgency for device manufacturers and users to apply patches.

Mitigation and Recommendations

Qualcomm promptly released patches addressing these vulnerabilities, which have been forwarded to OEMs for integration into Android firmware updates. Due to the fragmentation of the Android ecosystem, rollout times vary widely, leaving many devices exposed.

Security experts recommend: • Immediate Updates: Users should regularly check for and install firmware updates from their device manufacturers. • App Vetting: Avoid downloading apps outside trusted sources like Google Play to minimize risk exposure. • Behavioral Monitoring: Users and enterprises should monitor devices for abnormal CPU/GPU usage, crashes, or suspicious network activity. • Enterprise Controls: Organizations should enforce mobile device management (MDM) policies to ensure timely patch deployment.

Broader Context

These vulnerabilities highlight the challenges inherent in securing low-level hardware drivers like GPUs, which often operate with high privileges and complex codebases. They remain attractive targets for advanced threat actors due to the potential for complete system compromise.

The incident reinforces the critical need for collaboration between chipset vendors, OS developers, and manufacturers to ensure rapid vulnerability identification and patch deployment, safeguarding the vast Android user base.

NIH on AI

https://grants.nih.gov/grants/guide/notice-files/NOT-OD-25-132.html
1•karljacob•3m ago•0 comments

A Eulogy to China's Art Museums

https://artreview.com/a-eulogy-to-chinas-art-museums-opinion-lai-fei/
1•bookofjoe•4m ago•0 comments

How much harm can wage-fixing cartels do?

https://www.promarket.org/2025/07/21/how-much-harm-can-wage-fixing-cartels-do/
1•hhs•6m ago•0 comments

Curl one-liner to repeatedly check a specific url

https://gist.github.com/oliveratgithub/7d9201b828c5156657c03a2fb6bd5941
1•inex•7m ago•0 comments

Malcolm-Jamal Warner, Who Played the Cosby Show's Theo, Drowns in Costa Rica

https://news.sky.com/story/malcolm-jamal-warner-who-played-the-cosby-shows-theo-drowns-in-costa-rica-13399852
1•austinallegro•8m ago•0 comments

Just launched my app – convert images to JPG, PNG, or PDF instantly, offline

https://apps.apple.com/au/app/image-converter-pdf-maker/id6748744676
1•preetigoel•8m ago•1 comments

BritCSS: Write CSS with British English Spellings

https://hackaday.com/2025/03/13/britcss-write-css-with-british-english-spellings/
1•mooreds•8m ago•0 comments

Lawfare Against Jerome Powell

https://www.scotsmanguide.com/news/fed-chair-responds-to-concerns-about-mismanaging-hq-renovations/
1•vedantnair•8m ago•0 comments

RRF Is Not Enough

https://softwaredoug.com/blog/2024/11/03/rrf-is-not-enough
1•kordlessagain•8m ago•0 comments

Neon Now Runs in VS Code

https://neon.com/blog/neon-now-runs-in-vs-code
1•giladkleinman•10m ago•0 comments

Why are aerospace parts so expensive?

https://twitter.com/gak_pdx/status/1939031705144435058
1•lr0•11m ago•0 comments

John Cramer, 90, to undergo mitochondrial transplantation in anti-aging attempt [pdf]

https://mitrix.bio/wp-content/uploads/2025/07/Cramer-Announcement-July-2025.pdf
1•birriel•13m ago•1 comments

Apple details how it trained its new AI models

https://9to5mac.com/2025/07/21/apple-details-how-it-trained-its-new-ai-models-4-interesting-highlights/
2•mgh2•16m ago•0 comments

What's Changing for UK Users Due to the UK Online Safety Act

https://support.discord.com/hc/en-us/articles/33362401287959-What-s-Changing-for-UK-Users-Due-to-the-UK-Online-Safety-Act
2•sanqui•16m ago•0 comments

Game Boy Photo Booth

https://there.oughta.be/a/game-boy-photo-booth
2•0xC0ncord•18m ago•0 comments

Let's Encrypt API Outage (acme-v02.api.letsencrypt.org)

https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/687e8d62b8a4e804fad85799
1•throwachimera•18m ago•0 comments

Garbage Collection for Systems Programmers

https://bitbashing.io/gc-for-systems-programmers.html
1•Bogdanp•20m ago•0 comments

Detecting LLM‑Generated 404s

https://www.bugsink.com/blog/hallucinated-404s/
1•vanschelven•22m ago•1 comments

10k companies at risk from Microsoft Sharepoint security flaw

https://9to5mac.com/2025/07/21/10000-companies-at-risk-from-microsoft-sharepoint-security-flaw/
3•mgh2•24m ago•0 comments

Prove me wrong, earn money!

https://nintil.com/prove-wrong-get-money
1•lr0•24m ago•0 comments

The Medium Chill

https://grist.org/living/2011-06-28-the-medium-chill/
1•toomuchtodo•25m ago•0 comments

Vibe Coding Gone Wrong: 5 Rules for Safely Using AI

https://cybercorsairs.com/my-ai-co-pilot-deleted-my-production-database/
1•todsacerdoti•26m ago•1 comments

Working on a Programming Language in the Age of LLMs

https://ryelang.org/blog/posts/programming-language-in-age-of-llms/
4•todsacerdoti•26m ago•1 comments

Scale AI's Ex-CMO on Surge AI

https://twitter.com/HarryStebbings/status/1947400212894650429
1•jasong•29m ago•0 comments

Figuring out why a nap might help people see things in new ways

https://arstechnica.com/science/2025/07/figuring-out-why-a-nap-might-help-people-see-things-in-new-ways/
1•PaulHoule•30m ago•0 comments

Got screwed by Product Hunt. Hackers, please help. Founders, this is a lesson

3•junlianglee•32m ago•2 comments

Show HN: Make the Most of Python's ExceptionGroups

https://github.com/mawildoer/groupie
2•mawildoer•34m ago•0 comments

Tracking stealth fighters and birds near aircraft with camera phones

https://www.youtube.com/watch?v=zFiubdrJqqI
1•lifeisstillgood•39m ago•0 comments

Reliable by Design: Fast, Fail-Safe AI Agents

https://www.aimon.ai/announcements/ife-200ms-instruction-following-evaluation-for-agentic-reflection/
2•pjoshi30•40m ago•0 comments

Claim: Meta offered $1.25B over four years to AI hire – and were refused

https://www.tomshardware.com/tech-industry/artificial-intelligence/abel-founder-claims-meta-offered-usd1-25-billion-over-four-years-to-ai-hire-person-still-said-no-despite-equivalent-of-usd312-million-yearly-salary
2•A_D_E_P_T•40m ago•0 comments