logo
Qualcomm fixes multiple zero-day chip flaws after Google warns of active exploits by hackers

Qualcomm fixes multiple zero-day chip flaws after Google warns of active exploits by hackers

India Today04-06-2025
Chipmaker Qualcomm has rolled out security patches to fix three serious zero-day vulnerabilities affecting its Adreno GPU (graphics processing unit) driver, after Google warned that hackers were actively exploiting these flaws in targeted attacks. The issues came to light after Google's Threat Analysis Group (TAG) shared evidence that the vulnerabilities — tracked as CVE-2025-21479, CVE-2025-21480, and CVE-2025-27038 — were being used in the wild. These flaws affect dozens of chipsets and could allow attackers to gain control of a device or install spyware.advertisement'There are indications from Google Threat Analysis Group that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation,' Qualcomm said in a security advisory on Monday.The first two vulnerabilities, CVE-2025-21479 and CVE-2025-21480, were reported to Qualcomm in January by Google's Android Security team. These issues are related to incorrect authorisation in the GPU's graphics framework, which can lead to memory corruption. The third flaw, CVE-2025-27038, was reported in March and is described as a use-after-free bug – a type of memory corruption that happens when a program continues to use memory after it has been freed.
The third vulnerability is believed to be connected to the rendering process in Chrome when using Adreno GPU drivers.Qualcomm said it provided patches for all three vulnerabilities to original equipment manufacturers (OEMs) in May. The company says that the patches for the issues affecting the Adreno Graphics Processing Unit (GPU) driver have been made available to OEMs in May together with a strong recommendation to deploy the update on affected devices as soon as possible.advertisementWhile the specific devices affected were not listed, Qualcomm advised users to contact their device makers for patch information. 'We encourage end users to apply security updates as they become available from device makers,' Qualcomm spokesperson Dave Schefcik said in a statement.Google also confirmed that its Pixel line of smartphones were not affected by these vulnerabilities, a Google spokesperson told TechCrunch.The situation is more serious for some Android users, as Google's TAG team also discovered signs of spyware being used alongside these flaws. According to a report from Bleeping Computer, TAG found evidence that attackers used these vulnerabilities to install a spyware called NoviSpy, which can bypass Android's built-in security and gain deep access to a device.The spyware was reportedly installed using a full exploit chain, which involves combining multiple bugs to bypass protections and gain control of the device at the kernel level, which is the deepest layer of the operating system.The discovery adds to growing concerns about how sophisticated threat actors are finding ways to exploit hardware and software vulnerabilities for targeted surveillance.With the fixes now available, Qualcomm and Google are urging phone makers to push the patches to users as soon as possible to prevent further misuse of these security holes. Users, in turn, are advised to keep their devices updated and stay alert for software updates issued by their phone manufacturers.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

ChatGPT beats all competitors in revenue generation from users: Report
ChatGPT beats all competitors in revenue generation from users: Report

Hans India

time26 minutes ago

  • Hans India

ChatGPT beats all competitors in revenue generation from users: Report

New Delhi: Individual users worldwide have spent $2 billion on the ChatGPT mobile app through iOS and Android platforms since the AI application's launch in May 2023, according to a report on Saturday. In 2025, revenue of the application grew 673 per cent year-over-year. The app has clocked 318 million downloads in 2025, 2.8 times higher than during the same period last year, TechCrunch reported. India has the highest lifetime installs at 13.7 per cent, while the US followed with 10.3 per cent. American users, however, accounted for over 38 per cent of ChatGPT's global revenue. Average spending per download in the US is $10, while in Germany it stood at 5.3 per cent. ChatGPT Users make payments for premium features, such as a ChatGPT Plus subscription at $20 per month, which provides access to advanced models like GPT-5, higher usage limits, and enhanced functionality. ChatGPT outperformed all competitors in lifetime revenue per install, averaging $2.91. Anthropic's Claude followed at $2.55, while Elon Musk's Grok stood at $0.75. Microsoft's Copilot app lagged at just $0.27. Analysts suggested Grok's underperformance is due to its late mobile launch. The standalone iOS app of xAI was only available to users from January 2025, with Android support added in March. The delay has hindered its momentum in the app economy. Meanwhile, Musk, the founder of xAI, claimed that OpenAI's ChatGPT ranks first on the Apple Store because of Apple's favouritism, while his apps, X and xAI's Grok, are sidelined. Apple denied allegations that its App Store algorithms or curated lists favour ChatGPT over Musk's offerings. 'The App Store is designed to be fair and free of bias,' the company insisted, adding that recommendations are based on charts, algorithms, and expert editorial curation using objective criteria, according to multiple media reports. GPT‑5 is available to all users, with Plus subscribers getting more usage and Pro subscribers getting access to GPT‑5 Pro, a version with extended reasoning for even more comprehensive and accurate answers.

Data centre owners urge U.S. Treasury to keep renewable energy subsidy rules
Data centre owners urge U.S. Treasury to keep renewable energy subsidy rules

The Hindu

time26 minutes ago

  • The Hindu

Data centre owners urge U.S. Treasury to keep renewable energy subsidy rules

The Data Center Coalition, which represents data center owners including Google, Amazon and Microsoft, called on U.S. Treasury Secretary Scott Bessent to uphold existing rules for wind and solar energy subsidies, saying they have enabled the industry to grow quickly and stay ahead of competition from China. Tougher rules on how projects can qualify for federal clean energy tax credits could slow development of new electricity generation at a time of surging power demand driven by artificial intelligence and the digital economy. "Any regulatory friction that slows down deployment of new generation today directly impacts our ability to meet AI-era electricity demands tomorrow," the coalition wrote in its letter to Bessent. The letter is dated August 4 but was seen by Reuters on Friday. U.S. President Donald Trump issued an executive order in July directing Treasury to tighten clean energy tax credit rules, including redefining what it means for a project to have started construction. The industry has relied on the existing rules for the last decade, and advisory firm Clean Energy Associates projected this week that the United States could lose about 60 gigawatts of planned solar capacity through 2030 if stricter "beginning of construction" rules are implemented. Between 2017 and 2023, the U.S. data center industry contributed $3.5 trillion to the nation's gross domestic product and directly employed over 600,000 workers, according to the DCC. The Treasury Department is expected to issue updated guidelines as soon as August 18.

Analyst Dan Ives's blunt take on Apple AI; says ‘No one on the Street believes…'
Analyst Dan Ives's blunt take on Apple AI; says ‘No one on the Street believes…'

Time of India

timean hour ago

  • Time of India

Analyst Dan Ives's blunt take on Apple AI; says ‘No one on the Street believes…'

Apple's artificial intelligence (AI) strategy is a 'disaster' and the company is falling far behind rivals such as Microsoft, Google, Meta and OpenAI, Wedbush analyst Dan Ives said in an interview with Bloomberg Tech. Ives said that Apple's internal AI efforts have failed to impress, pointing to Siir as an example. 'Nothing's going to happen internally,' he said, adding, 'It's not happening internally and there's no one on the Street that believes any innovation is coming out of Apple when it comes to AI organically.' Speaking on the show, Dan Ives reiterated that Apple will need acquisitions and partnerships to stay competitive. 'They're going to have to do an acquisition. I mean, look, it's the reality of the situation,' he said. He has previously suggested a three-pronged plan for Apple: acquire AI search firm Perplexity, recruit top AI talent, and consider integrating Google's Gemini AI. Ives also warned that Apple's slow AI growth could affect CEO Tim Cook's legacy. He said competitors are moving aggressively in AI and Apple must act quickly to secure its place in the next technological revolution. by Taboola by Taboola Sponsored Links Sponsored Links Promoted Links Promoted Links You May Like Redefine Your Future with a Top Online MBA SRM Online Enquire Now Undo Apple has more than 2.4 billion iOS devices worldwide, which gives it a strong consumer base. However, Ives said without a bold AI plan, Apple's leadership could be challenged by rivals. When Dan Ives said it is time for Apple to make an acquisition This is not the first time Dan Ives has criticized Apple. After the company's Worldwide Developers Conference (WWDC) in June, he wrote in a research note that it 'felt like an episode out of 'Back to the Future'', especially when it came to Apple's treatment of AI. 'Barely no mention of AI,' Ives then remarked, calling it 'the elephant in the room.' 'It's becoming crystal clear that any innovation around AI at Apple is not coming from inside the walls of Apple Park,' he then said. Ives wrote that 'the time has come' for Apple to make a big acquisition, calling Perplexity a 'no brainer' target. He said such a deal could quickly boost Apple's weak AI platform and turn Siri into the 'next AI gateway for consumers.' Investor to Apple: Change your CEO Last month, analysts at LightShed Partners said that Apple may need a leadership change to better focus on product innovation, especially in the area of artificial intelligence (AI). In a note published on July 09), the analysts said that while CEO Tim Cook brought operational expertise to the top job, the company now 'needs a product-focused CEO.' 'To be clear, Tim Cook was the right CEO at the time of his appointment and unquestionably has done a great job,' the analysts wrote. 'Apple has sold over $2.0 trillion of iPhones with Cook as CEO. In fact, iPhone sales could show signs of life this quarter, as tariff-related pull-forwards help stabilize replacement cycles that may finally be bottoming out.' AI Masterclass for Students. Upskill Young Ones Today!– Join Now

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store