CVE-2025-27038
HIGHCVSS 7.5/10Actively ExploitedEPSS 0.80%
Last modified
CVE-2025-27038 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.. CISA has confirmed active exploitation in the wild. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Ar8031 Firmware | All versions |
| Qualcomm | Csra6620 Firmware | All versions |
| Qualcomm | Csra6640 Firmware | All versions |
| Qualcomm | Fastconnect 7800 Firmware | All versions |
| Qualcomm | Qca2066 Firmware | All versions |
| Qualcomm | Qca6391 Firmware | All versions |
| Qualcomm | Qcm6125 Firmware | All versions |
| Qualcomm | Qcm8550 Firmware | All versions |
| Qualcomm | Qcn9011 Firmware | All versions |
| Qualcomm | Qcn9012 Firmware | All versions |
| Qualcomm | Qcs6125 Firmware | All versions |
| Qualcomm | Qcs8550 Firmware | All versions |
| Qualcomm | Video Collaboration Vc1 Platform Firmware | All versions |
| Qualcomm | Sm6475 Firmware | All versions |
| Qualcomm | Sm6650 Firmware | All versions |
| Qualcomm | Sm6650p Firmware | All versions |
| Qualcomm | Sm7435 Firmware | All versions |
| Qualcomm | Sm7635 Firmware | All versions |
| Qualcomm | Sm7635p Firmware | All versions |
| Qualcomm | Smart Audio 400 Platform Firmware | All versions |
| Qualcomm | Snapdragon 4 Gen 2 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 6 Gen 1 Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 680 4g Mobile Platform Firmware | All versions |
| Qualcomm | Snapdragon 685 4g Mobile Platform \(Sm6225-Ad\) Firmware | All versions |
| Qualcomm | Snapdragon W5\+ Gen 1 Wearable Platform Firmware | All versions |
| Qualcomm | Sw5100 Firmware | All versions |
| Qualcomm | Sw5100p Firmware | All versions |
| Qualcomm | Wcd9335 Firmware | All versions |
| Qualcomm | Wcd9370 Firmware | All versions |
| Qualcomm | Wcd9375 Firmware | All versions |
| Qualcomm | Wcd9378 Firmware | All versions |
| Qualcomm | Wcd9385 Firmware | All versions |
| Qualcomm | Wcd9395 Firmware | All versions |
| Qualcomm | Wcn3950 Firmware | All versions |
| Qualcomm | Wcn3980 Firmware | All versions |
| Qualcomm | Wcn3988 Firmware | All versions |
| Qualcomm | Wcn6650 Firmware | All versions |
| Qualcomm | Wcn6740 Firmware | All versions |
| Qualcomm | Wcn6755 Firmware | All versions |
| Qualcomm | Wsa8810 Firmware | All versions |
| Qualcomm | Wsa8815 Firmware | All versions |
| Qualcomm | Wsa8830 Firmware | All versions |
| Qualcomm | Wsa8832 Firmware | All versions |
| Qualcomm | Wsa8835 Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-27038?
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
How severe is CVE-2025-27038?
CVE-2025-27038 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.80% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2025-27038?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-27031memory corruption while processing IOCTL commands, when the …7.8
- CVE-2025-27032memory corruption while loading a PIL authenticated VM, when…7.8
- CVE-2025-27033Information disclosure while running video usecase having ro…6.1
- CVE-2025-27034Memory corruption while selecting the PLMN from SOR failed l…9.8
- CVE-2025-27036Information disclosure when Video engine escape input data i…6.1
- CVE-2025-27037Memory corruption while processing config_dev IOCTL when cam…7.8
- CVE-2025-27039Memory corruption may occur while processing IOCTL call for …6.6
- CVE-2025-2704OpenVPN version 2.6.1 through 2.6.13 in server mode using TL…7.5
- CVE-2025-27040Information disclosure may occur while processing the hyperv…6.5
- CVE-2025-27041Transient DOS while processing video packets received from v…5.5
- CVE-2025-27042Memory corruption while processing video packets received fr…7.8
- CVE-2025-27043Memory corruption while processing manipulated payload in vi…7.8
Are you affected by CVE-2025-27038?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
