Vulnerabilities & Exploits · Zero-Day Exploit

Actively Exploited Qualcomm Zero‑Day Hits Android Chipsets

Google disclosed a memory‑corruption zero‑day, CVE‑2026‑21385, in an open‑source Qualcomm display component. Google marked it as actively exploited and Qualcomm says it affects 234–235 chipsets.

6 sources · Mar 3

CVE-2026-21385

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: memory corruption while using alignments for memory allocation.

CISA federal remediation date Mar 24

Timeline

Sources

Part of the PlainSec briefing for 2026-03-03

Every edition of this story: Actively Exploited Qualcomm Zero‑Day Hits Android Chipsets

More from today