The first entry is always the pin's source. Overall confidence is a weighted average of how firmly each reference supports the start and end times used above; a reference counts half as much for every 180 days older than the newest.
BleepingComputer's[2][4] 2 June 2025 report quotes 'a Monday advisory' in which Qualcomm said 'There are indications from Google Threat Analysis Group that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation'.
Follow-up: Google folded the fixes for CVE-2025-21479 and CVE-2025-27038 into Android's August 2025 security update.[1]
CISA's KEV entry: 'Qualcomm[1] Multiple Chipsets Incorrect Authorization Vulnerability', added 3 June 2025, due 24 June 2025 (CVE-2025-21480 and CVE-2025-27038 were added the same day).
Quotes Qualcomm's[1] Monday advisory on exploitation and on patches reaching OEMs in May; CVE-2025-21479 and -21480 reported in late January and CVE-2025-27038 in March via the Google Android Security team.
CVSS 8.6 for the two incorrect-authorization flaws in GPU microcode and 7.5 for the Chrome-rendering use-after-free; recalls earlier Qualcomm[1] flaws used by commercial spyware vendors.
Something missing or wrong? Say it in your own words: a link that backs this pin up, a different start or end date and why, or a fact it lacks or gets wrong. The AI checks it against this pin's sources, searches for better ones, and adds any page that backs you up. The pin's own sources still count most.