CVE-2025-21479

HIGH KEV

Qualcomm AQT1000 and FastConnect Firmware - Memory Corruption via Unauthorized GPU Micronode Command Execution

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-21479 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 3, 2025. EIP tracks 5 public exploits from researchers including zhuowei, sarabpal-dev, CamsShaft.

AI-analyzed exploit summary This repository contains a root exploit for the Quest 3/3S devices leveraging CVE-2025-21479, a vulnerability in the Adreno GPU (A7xx series). The exploit manipulates the IB (Instruction Buffer) level to bypass security checks and achieve privilege escalation.

Description

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

Exploits (5)

nomisec WORKING POC 200 stars
by zhuowei · local
https://github.com/zhuowei/cheese

This repository contains a root exploit for the Quest 3/3S devices leveraging CVE-2025-21479, a vulnerability in the Adreno GPU (A7xx series). The exploit manipulates the IB (Instruction Buffer) level to bypass security checks and achieve privilege escalation.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Qualcomm Adreno GPU (A7xx series) on Quest 3/3S devices
No auth needed
Prerequisites: Device running vulnerable firmware (Quest 3/3S with firmware versions before August 7, 2025)
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 17 stars
by sarabpal-dev · local
https://github.com/sarabpal-dev/cheese-cake

This repository contains a proof-of-concept exploit for CVE-2025-21479, targeting a vulnerability in Qualcomm Adreno GPU drivers. The exploit leverages GPU memory manipulation to achieve arbitrary read/write primitives in kernel memory, likely for local privilege escalation (LPE).

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Qualcomm Adreno GPU driver (specific version not explicitly stated)
No auth needed
Prerequisites: Access to a vulnerable Qualcomm Adreno GPU device · Kernel memory layout knowledge (e.g., kallsyms)
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
github WORKING POC 2 stars
by CamsShaft · cpoc
https://github.com/CamsShaft/SELinux-Permissive-Only-CVE-2025-21479

This repository contains a functional local privilege escalation (LPE) exploit for CVE-2025-21479, targeting Samsung S22/S22U devices running kernel 5.10 and Android 14. The exploit leverages a GPU memory corruption vulnerability to achieve SELinux permissive mode from an untrusted Termux environment without requiring ADB.

Classification
Working Poc 98%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: Samsung S22/S22U (SM-S901W/SM-S908W) kernel 5.10, Android 14
No auth needed
Prerequisites: Target device must be Samsung S22/S22U with vulnerable kernel · Termux environment on the device · kallsyms.txt file for symbol resolution · Access to /dev/kgsl-3d0 GPU device
mistral-large-3 · analyzed Jul 28, 2026 Full analysis →
nomisec WORKING POC
by CamsShaft · local
https://github.com/CamsShaft/SELinux-Permissive-Only-version-of-Cheese-aka-CVE-2025-21479

This repository contains a functional local privilege escalation (LPE) exploit for CVE-2025-21479, targeting Samsung S22/S22U devices running kernel 5.10 and Android 14. The exploit leverages a GPU memory corruption vulnerability to achieve SELinux permissive mode from an untrusted Termux environment without requiring ADB.

Classification
Working Poc 98%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: Samsung S22/S22U (SM-S901W/SM-S908W) kernel 5.10, Android 14
No auth needed
Prerequisites: Target device must be Samsung S22/S22U with vulnerable kernel · Termux environment on the device · kallsyms.txt file for symbol resolution · Access to /dev/kgsl-3d0 GPU device
mistral-large-3 · analyzed Jul 28, 2026 Full analysis →
github WORKING POC
by ma4the · clocal
https://github.com/ma4the/omae-wa-cheese-da

This repository contains a functional exploit for CVE-2025-21479, targeting the Galaxy Z Flip 5's GPU to achieve arbitrary physical read/write, KASLR leak, SELinux permissive mode, and a resident root server. The exploit leverages GPU command manipulation and page table setup to escalate privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Samsung Galaxy Z Flip 5 (SM-F731N) with firmware F731NKSU5EYD9
No auth needed
Prerequisites: Device with vulnerable GPU firmware (Adreno 740 v2) · Security patch before August 2025 · ADB access
mistral-large-3 · analyzed Jun 19, 2026 Full analysis →

Scores

CVSS v3 8.6
EPSS 0.0078
EPSS Percentile 52.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2025-06-03
VulnCheck KEV 2025-06-02
ENISA EUVD EUVD-2025-16710
CWE
CWE-863
Status published
Products (50)
qualcomm/aqt1000_firmware
qualcomm/fastconnect_6200_firmware
qualcomm/fastconnect_6700_firmware
qualcomm/fastconnect_6800_firmware
qualcomm/fastconnect_6900_firmware
qualcomm/fastconnect_7800_firmware
qualcomm/qca6391_firmware
qualcomm/qcm4490_firmware
qualcomm/qcs4490_firmware
qualcomm/sd855_firmware
... and 40 more
Published Jun 03, 2025
KEV Added Jun 03, 2025
Tracked Since Feb 18, 2026