Android Phones Based on Qualcomm Chip Threatened, Google Asks Users to Update Immediately

The discovery of security loopholes on Android phones that threatens millions of users
Some time ago, there were quite serious security holes on Android phones, especially on devices that use the Snapdragon chipset from Qualcomm. This gap raises big concerns because it potentially harms user data and allows unauthorized access to the device.
This security hole was revealed by the Google Threat Analysis Group (TAG), Google’s internal team that focuses on monitoring cybersecurity threats, including hacking activities carried out by state actors or high-ability groups. In their report, two malicious bugs were found in the Adreno GPU component, an important part of the Snapdragon chipset used on many Android devices, ranging from middle-class to flagship.
Types of security vulnerabilities found
The two main security vulnerabilities found were CVE-2025-21479 and CVE-2025-27038. These two gaps are known to be being exploited by hackers.
CVE-2025-21479 has a score of 8.6 out of 10, which indicates a very high severity. This bug allows hackers to run certain commands that can damage GPU memory. Meanwhile, CVE-2025-27038 has a score of 7.5 out of 10 and can cause disruption to system memory when the device displays graphics in a browser such as Chrome.
If exploited, these two loopholes can be used to steal sensitive data, take over the device, or even install spyware. Tag says that this gap has been used in targeted attacks, perhaps against important figures such as diplomats, journalists, or scientists. In addition, the United States cyber security agency, CISA, also included these two gaps in the Known Exploited Vulnerabilities (KEV) list.
Response from Qualcomm and Google
Qualcomm has released patches for this gap since May 2025 and asked OEMs such as Samsung, Xiaomi, and others to implement it immediately. In a statement, Qualcomm stated that the patch for the problem on the Adreno GPU driver has been available for OEMs since May, and they strongly recommend that the update be implemented immediately.
Google then integrates the patch in the August 2025 Android security update. There are two sets of patches released, namely the security patch level 2025-08-01 and 2025-08-05. The last patch combines all the fixes from the first wave as well as the patch for the kernel sub-component and private third-party, though it may not apply to all Android devices.
According to the Bleeping Computer report, the August 2025 security patch has been first deployed to Pixel devices and will soon arrive at devices from other vendors in stages. However, due to the decentralized Android structure, this update will reach various devices at different times.
Steps that the user must take
Android smartphone users are advised to:
- Check for security updates in the “Settings” menu > “Software Update”.
- Make sure you get a patch 2025-08-01 or 2025-08-05.
- Activate automatic updates so as not to miss future patches.
- Perform regular checks to ensure the device remains safe.
So far, several Android devices from brands such as Samsung, Realme, and Tecno have not received the August security patch 2025. Most likely, new updates will come in some time to come. Therefore, users must remain vigilant and actively update their device.























