CVE-2025-21424
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 3, 2025
Updated: Mar 7, 2025
CWE ID 416
Summary
CVE-2025-21424 is a newly discovered vulnerability affecting NPU (Neural Processing Unit) driver APIs. This issue results in memory corruption when these APIs are called concurrently, potentially leading to arbitrary code execution or denial of service. An attacker could exploit this flaw by sending specially crafted requests to the NPU driver, causing it to corrupt memory and gain unauthorized access or cause the device to crash. Users are advised to apply the forthcoming patch as soon as it becomes available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.