-
CVE-2025-6573: About Imagination’s PowerVR DDK (12th AUG 2025)
Preface: PowerVR is a brand of graphics processing unit (GPU) IP ( intellectual property) developed by Imagination Technologies. In the context of Android, PowerVR GPUs are integrated into mobile System-on-Chips (SoCs) by various manufacturers, providing the graphics processing capabilities for Android devices. It’s a key competitor to Adreno (Qualcomm) and Mali (Arm) GPUs in the…
-
CVE-2025-0932: Arm fixes userspace vulnerability in Mali GPU driver (8th Aug 2025)
Preface: The Valhall family of Mali GPUs uses the same top-level architecture as the previous generation Bifrost GPUs. The Valhall family uses a unified shader core architecture. The Arm 5th generation GPU architecture, including the Immortalis and Mali GPUs, represents a modern design for mobile and other client devices. Background: ioctl (Input/Output Control) is the…
-
CVE-2025-43209: Processing maliciously crafted web content may lead to an unexpected Safari crash (31-07-2025)
Preface: In essence, built-in browsers are not just about browsing; they are about maintaining control over the core functionality and user experience of the operating system. Background: Safari and Edge, while built-in, utilize rendering engines derived from the KHTML project, specifically WebKit and Blink, respectively. WebKit is used in Safari, and Blink, a fork of…
-
CVE-2025-21432: Double Free in SPS-HLOS (8th July 2025)
Preface: Concise Binary Object Representation (CBOR) is a binary data serialization format loosely based on JSON authored by Carsten Bormann. The use of Concise Binary Object Representation (CBOR) in SPS HLOS (and other constrained environments) is primarily due to its ability to provide a compact, efficient, and extensible binary data format. This makes it suitable…
-
CVE-2025-21450: Improper Authentication in GPS GNSS (7th July 2025)
Preface: GNSS – This is a global term encompassing all satellite constellations that provide positioning, navigation, and timing (PNT) services. Besides GPS, other GNSS include GLONASS (Russia), Galileo (EU), and BeiDou (China). GPS – The Global Positioning System, developed by the US Department of Defense, is the most widely recognized and used GNSS. It was…
-
CVE-2025-44952: About Open5GS (19-6-2025)
Preface: Open5GS is a popular open-source 5G core network (5GC) implementation, particularly among researchers and those building private 5G networks. It’s recognized as one of the leading open-source 5GC projects. Open5GS is known for its adherence to 3GPP standards and its mature development, making it suitable for various applications like testbeds, research, and even some…
-
CVE-2025-2884 – Design weakness in the Trusted Platform Module (TPM) 2.0 reference implementation code. (11th June 2025)
Preface: The main difference between AMD’s Trusted Platform Module (TPM) and those from other manufacturers , how it’s implemented: AMD offers a firmware TPM (fTPM), while many other manufacturers, including Intel, also offer a dedicated hardware TPM (dTPM). Background: TPM refers to a Trusted Platform Module, which is a specialized chip that securely stores cryptographic…
-
CVE-2025-0037: About AMD Versal™ Adaptive SoC – Initial publication 2025-06-03
(9th June 2025) Preface: AMD’s Versal™ Adaptive SoCs are used in a wide range of industries, particularly those requiring high-performance, low-latency processing and flexibility, such as data centers, wireless networking, automotive, aerospace, and defense. Versal chips are also utilized in areas like 5G wireless, advanced driver assist, and even 3D printing. AMD’s Versal™ Adaptive SoC…
-
CVE-2025-1246: A non-privileged user process can perform valid GPU processing operations (8th June 2025)
Preface: The Valhall family of Mali GPUs uses the same top-level architecture as the previous generation Bifrost GPUs. The Valhall family uses a unified shader core architecture. Arm’s 5th generation GPU architecture, on the other hand, is a type of GPU architecture that is designed for visual computing, especially on mobile devices, and includes features…
-
CVE-2024-49835 – Out-of-bounds Write in SPS Applications (8th May 2025)
Preface: Semi-Persistent Scheduling (SPS) is used in LTE and 5G networks to reduce control channel overhead for applications requiring persistent radio resource allocations, such as VoIP and VoLTE . The memory usage for SPS on Android devices can vary based on several factors, including the specific implementation and the network conditions. A method and apparatus…