CVE-2025-21480

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 4 articles

EPSS Score

Source: FIRST.org · 2026-05-24
2.0%
probability
This CVE has a 2.0% probability of being exploited in the next 30 days.
0% Top 83.9th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Arbitrary physical write vulnerability

Attack Intelligence

Google Project Zero

Patched
June 2, 2025
Reported by
Google Threat Analysis Group
Root Cause Analysis
???

Signal Intelligence

Confidence
92%
EPSS 2.0%
Mentions 4
Last Seen Aug 05, 2025

CNA Information

Analyst Note

CVE-2025-21480 is confirmed as a zero-day with active exploitation in the wild, as evidenced by Qualcomm's release of patches for multiple Adreno GPU zero-days and multiple high-signal security publications reporting attacks. The high CVSS score (8.6) combined with Google Project Zero tracking and documented exploitation in real-world attacks provides strong confirmation of this vulnerability's severity and active threat status.

Triage Info

Decided atMar 03, 2026