CVE-2025-21480
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
4 articles
EPSS Score
Source: FIRST.org · 2026-05-24
2.0%
probability
This CVE has a 2.0% probability
of being exploited in the next 30 days.
0%
Top 83.9th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroArbitrary physical write vulnerability
Attack Intelligence
Google Project Zero
Patched
June 2, 2025
Reported by
Google Threat Analysis Group
Root Cause Analysis
???
Android gets patches for Qualcomm flaws exploited in attacks
BleepingComputer
Aug 05, 2025
Qualcomm fixes three Adreno GPU zero-days exploited in attacks
BleepingComputer
Jun 02, 2025
Signal Intelligence
Confidence
92%
EPSS
2.0%
Mentions
4
Last Seen
Aug 05, 2025
CNA Information
Analyst Note
CVE-2025-21480 is confirmed as a zero-day with active exploitation in the wild, as evidenced by Qualcomm's release of patches for multiple Adreno GPU zero-days and multiple high-signal security publications reporting attacks. The high CVSS score (8.6) combined with Google Project Zero tracking and documented exploitation in real-world attacks provides strong confirmation of this vulnerability's severity and active threat status.
Triage Info
Decided atMar 03, 2026