CVE-2025-27038

HIGH KEV

Qualcomm AR8031 Firmware - Use-After-Free in Adreno GPU Driver

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-27038 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 3, 2025.

Description

Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

Scores

CVSS v3 7.5
EPSS 0.0137
EPSS Percentile 80.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2025-06-03
VulnCheck KEV 2025-06-02
ENISA EUVD EUVD-2025-16700
CWE
CWE-416
Status published
Products (44)
qualcomm/ar8031_firmware
qualcomm/csra6620_firmware
qualcomm/csra6640_firmware
qualcomm/fastconnect_7800_firmware
qualcomm/qca2066_firmware
qualcomm/qca6391_firmware
qualcomm/qcm6125_firmware
qualcomm/qcm8550_firmware
qualcomm/qcn9011_firmware
qualcomm/qcn9012_firmware
... and 34 more
Published Jun 03, 2025
KEV Added Jun 03, 2025
Tracked Since Feb 18, 2026