CVE-2026-21385
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: memory corruption while using alignments for memory allocation.
Data di correzione federale CISA 24 mar
Vulnerabilità ed exploit · Exploit zero-day
Google ha divulgato una vulnerabilità di memory‑corruption (CVE‑2026‑21385) in un componente display Qualcomm open‑source. Google segnala sfruttamento attivo; Qualcomm indica che la falla interessa 234–235 chipset e ha rilasciato patch ai OEM a gennaio 2026.
6 fonti · 3 mar
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: memory corruption while using alignments for memory allocation.
Data di correzione federale CISA 24 mar
Dark Reading
Qualcomm Zero-Day Exploited in Targeted Android Attacks
The exploitation of CVE-2026-21385, a high-severity memory corruption flaw, could be tied to commercial spyware or nation-state threat groups.
originaleSecurityWeek
Android Update Patches Exploited Qualcomm Zero-Day
An integer overflow or wraparound in the Qualcomm graphics component, the bug leads to memory corruption.
originaleThe Hacker News
Google Confirms CVE-2026-21385 in Qualcomm Android Component Exploited
Google’s March 2026 Android update patches 129 vulnerabilities, including exploited Qualcomm flaw CVE-2026-21385 and critical RCE CVE-2026-0006.
originalePart of the PlainSec briefing for 2026-03-03
Every edition of this story: Zero‑day Qualcomm attivamente sfruttato su chipset Android