CVE-2025-27038

HIGH CISA KEV
Published Jun 3, 2025 Modified Oct 27, 2025 CWE-416

Description

Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

CVSS v3.1 Score

7.5
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild.

Added: Jun 3, 2025 Remediation due: Jun 24, 2025

Weakness Type (CWE)

CWE-416 Use After Free

Affected Products

Vendor Product
qualcomm ar8031_firmware
qualcomm ar8031
qualcomm csra6620_firmware
qualcomm csra6620
qualcomm csra6640_firmware
qualcomm csra6640
qualcomm fastconnect_7800_firmware
qualcomm fastconnect_7800
qualcomm qca2066_firmware
qualcomm qca2066
qualcomm qca6391_firmware
qualcomm qca6391
qualcomm qcm6125_firmware
qualcomm qcm6125
qualcomm qcm8550_firmware
qualcomm qcm8550
qualcomm qcn9011_firmware
qualcomm qcn9011
qualcomm qcn9012_firmware
qualcomm qcn9012
qualcomm qcs6125_firmware
qualcomm qcs6125
qualcomm qcs8550_firmware
qualcomm qcs8550
qualcomm video_collaboration_vc1_platform_firmware
qualcomm video_collaboration_vc1_platform
qualcomm sm6475_firmware
qualcomm sm6475
qualcomm sm6650_firmware
qualcomm sm6650
qualcomm sm6650p_firmware
qualcomm sm6650p
qualcomm sm7435_firmware
qualcomm sm7435
qualcomm sm7635_firmware
qualcomm sm7635
qualcomm sm7635p_firmware
qualcomm sm7635p
qualcomm smart_audio_400_platform_firmware
qualcomm smart_audio_400_platform
qualcomm snapdragon_4_gen_2_mobile_platform_firmware
qualcomm snapdragon_4_gen_2_mobile_platform
qualcomm snapdragon_6_gen_1_mobile_platform_firmware
qualcomm snapdragon_6_gen_1_mobile_platform
qualcomm snapdragon_680_4g_mobile_platform_firmware
qualcomm snapdragon_680_4g_mobile_platform
qualcomm snapdragon_685_4g_mobile_platform_\(sm6225-ad\)_firmware
qualcomm snapdragon_685_4g_mobile_platform_\(sm6225-ad\)
qualcomm snapdragon_w5\+_gen_1_wearable_platform_firmware
qualcomm snapdragon_w5\+_gen_1_wearable_platform
qualcomm sw5100_firmware
qualcomm sw5100
qualcomm sw5100p_firmware
qualcomm sw5100p
qualcomm wcd9335_firmware
qualcomm wcd9335
qualcomm wcd9370_firmware
qualcomm wcd9370
qualcomm wcd9375_firmware
qualcomm wcd9375
qualcomm wcd9378_firmware
qualcomm wcd9378
qualcomm wcd9385_firmware
qualcomm wcd9385
qualcomm wcd9395_firmware
qualcomm wcd9395
qualcomm wcn3950_firmware
qualcomm wcn3950
qualcomm wcn3980_firmware
qualcomm wcn3980
qualcomm wcn3988_firmware
qualcomm wcn3988
qualcomm wcn6650_firmware
qualcomm wcn6650
qualcomm wcn6740_firmware
qualcomm wcn6740
qualcomm wcn6755_firmware
qualcomm wcn6755
qualcomm wsa8810_firmware
qualcomm wsa8810
qualcomm wsa8815_firmware
qualcomm wsa8815
qualcomm wsa8830_firmware
qualcomm wsa8830
qualcomm wsa8832_firmware
qualcomm wsa8832
qualcomm wsa8835_firmware
qualcomm wsa8835

References

Frequently Asked Questions

What is CVE-2025-27038? +
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome. It has a CVSS v3.1 base score of 7.5 (HIGH). This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.
How severe is CVE-2025-27038? +
CVE-2025-27038 has a CVSS v3.1 score of 7.5 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2025-27038? +
CVE-2025-27038 affects products from qualcomm, specifically: ar8031, ar8031_firmware, csra6620, csra6620_firmware, csra6640, csra6640_firmware, fastconnect_7800, fastconnect_7800_firmware, qca2066, qca2066_firmware, qca6391, qca6391_firmware, qcm6125, qcm6125_firmware, qcm8550, qcm8550_firmware, qcn9011, qcn9011_firmware, qcn9012, qcn9012_firmware, qcs6125, qcs6125_firmware, qcs8550, qcs8550_firmware, sm6475, sm6475_firmware, sm6650, sm6650_firmware, sm6650p, sm6650p_firmware, sm7435, sm7435_firmware, sm7635, sm7635_firmware, sm7635p, sm7635p_firmware, smart_audio_400_platform, smart_audio_400_platform_firmware, snapdragon_4_gen_2_mobile_platform, snapdragon_4_gen_2_mobile_platform_firmware, snapdragon_680_4g_mobile_platform, snapdragon_680_4g_mobile_platform_firmware, snapdragon_685_4g_mobile_platform_\(sm6225-ad\), snapdragon_685_4g_mobile_platform_\(sm6225-ad\)_firmware, snapdragon_6_gen_1_mobile_platform, snapdragon_6_gen_1_mobile_platform_firmware, snapdragon_w5\+_gen_1_wearable_platform, snapdragon_w5\+_gen_1_wearable_platform_firmware, sw5100, sw5100_firmware, sw5100p, sw5100p_firmware, video_collaboration_vc1_platform, video_collaboration_vc1_platform_firmware, wcd9335, wcd9335_firmware, wcd9370, wcd9370_firmware, wcd9375, wcd9375_firmware, wcd9378, wcd9378_firmware, wcd9385, wcd9385_firmware, wcd9395, wcd9395_firmware, wcn3950, wcn3950_firmware, wcn3980, wcn3980_firmware, wcn3988, wcn3988_firmware, wcn6650, wcn6650_firmware, wcn6740, wcn6740_firmware, wcn6755, wcn6755_firmware, wsa8810, wsa8810_firmware, wsa8815, wsa8815_firmware, wsa8830, wsa8830_firmware, wsa8832, wsa8832_firmware, wsa8835, wsa8835_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-27038? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-27038 — free, no signup required.

Start Free Scan