Android gets patches for Qualcomm flaws exploited in attacks
Two Qualcomm issues that were used in targeted assaults are among the six vulnerabilities in Android's August 2025 security update for which Google has issued security patches.
The Google Android Security team received reports of the two security flaws in late January 2025, and they were identified as CVE-2025-21479 and CVE-2025-27038.
The first is an improper authorization flaw in the graphics framework that can cause memory corruption by allowing unauthorized commands to be executed in the GPU micronode when carrying out a particular command sequence. In contrast, CVE-2025-27038 is a use-after-free vulnerability that corrupts memory when Chrome's Adreno GPU drivers are used to generate graphics.
The Google Threat Analysis Group has now incorporated the updates that Qualcomm iss...

