More

    Phone chipmaker Qualcomm fixes three zero-days exploited by hackers


    Chipmaker big Qualcomm launched patches on Monday fixing a collection of vulnerabilities in dozens of chips, together with three zero-days that the corporate stated could also be in use as a part of hacking campaigns. 

    Qualcomm cited Google’s Threat Analysis Group, or TAG, which investigates government-backed cyberattacks, saying the three flaws “could also be underneath restricted, focused exploitation.” 

    According to the corporate’s bulletin, Google’s Android safety workforce reported the three zero-days (CVE-2025-21479, CVE-2025-21480, and CVE-2025-27038) to Qualcomm in February. Zero-days are safety vulnerabilities that aren’t recognized to the software program or {hardware} maker on the time of their discovery, making them extraordinarily precious for cybercriminals and authorities hackers. 

    Because of Android’s open supply and distributed nature, it’s now as much as machine producers to use the patches offered by Qualcomm, which suggests some units should still be susceptible for a number of extra weeks, even though there are patches out there. 

    Contact Us

    Do you will have extra details about these Qualcomm zero-days? Or different zero-day exploits or zero-day makers? From a non-work machine and community, you’ll be able to contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or through Telegram and Keybase @lorenzofb, or e mail.

    Qualcomm stated within the bulletin that the patches “have been made out there to [device makers] in May along with a powerful advice to deploy the replace on affected units as quickly as doable.”

    Google spokesperson Ed Fernandez advised TechCrunch that the corporate’s Pixel units are usually not affected by these Qualcomm vulnerabilities.

    When reached by TechCrunch, a spokesperson for Google’s TAG didn’t instantly present extra details about these vulnerabilities, and the circumstances through which TAG discovered them. 

    Qualcomm didn’t reply to a request for remark.

    Chipsets present in cell units are frequent targets for hackers and zero-day exploit builders as a result of chips typically have vast entry to the remainder of the working system, which suggests hackers can bounce from there to different components of the machine which will maintain delicate knowledge. 

    In the previous couple of months, there have been documented circumstances of exploitation in opposition to Qualcomm chipsets. Last yr, Amnesty International recognized a Qualcomm zero-day that was being utilized by Serbian authorities, possible by utilizing telephone unlocking instrument maker Cellebrite.



    Source hyperlink

    Recent Articles

    spot_img

    Related Stories

    Leave A Reply

    Please enter your comment!
    Please enter your name here

    Stay on op - Ge the daily news in your inbox