CVE-2026-21385
Known exploited · CISA KEV
CVSS 7.8 HIGH: memory corruption while using alignments for memory allocation.
CISA federal remediation date Mar 24
Vulnerabilities & Exploits · Zero-Day Exploit
Google disclosed CVE-2026-21385, a memory‑corruption bug in a Qualcomm graphics/display component.
6 sources · Mar 3
Known exploited · CISA KEV
CVSS 7.8 HIGH: memory corruption while using alignments for memory allocation.
CISA federal remediation date Mar 24
Dark Reading
Qualcomm Zero-Day Exploited in Targeted Android Attacks
The exploitation of CVE-2026-21385, a high-severity memory corruption flaw, could be tied to commercial spyware or nation-state threat groups.
originalSecurityWeek
Android Update Patches Exploited Qualcomm Zero-Day
An integer overflow or wraparound in the Qualcomm graphics component, the bug leads to memory corruption.
originalThe Hacker News
Google Confirms CVE-2026-21385 in Qualcomm Android Component Exploited
Google’s March 2026 Android update patches 129 vulnerabilities, including exploited Qualcomm flaw CVE-2026-21385 and critical RCE CVE-2026-0006.
originalPart of the PlainSec briefing for 2026-03-04
Every edition of this story: Actively Exploited Qualcomm Zero‑Day Hits Android Chipsets