CVE-2026-21385
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: memory corruption while using alignments for memory allocation.
Data di correzione federale CISA 24 mar
Vulnerabilità ed exploit · Exploit zero-day
Si tratta di un integer overflow che può causare memory corruption; la vulnerabilità ha CVSS 7.8. Google segnala indicazioni di sfruttamento limitato e mirato su dispositivi con chipset Qualcomm.
6 fonti · 3 mar
Sfruttamento noto · CISA KEV
CVSS 7.8 HIGH: memory corruption while using alignments for memory allocation.
Data di correzione federale CISA 24 mar
Dark Reading
Qualcomm Zero-Day Exploited in Targeted Android Attacks
The exploitation of CVE-2026-21385, a high-severity memory corruption flaw, could be tied to commercial spyware or nation-state threat groups.
originaleSecurityWeek
Android Update Patches Exploited Qualcomm Zero-Day
An integer overflow or wraparound in the Qualcomm graphics component, the bug leads to memory corruption.
originaleThe Hacker News
Google Confirms CVE-2026-21385 in Qualcomm Android Component Exploited
Google’s March 2026 Android update patches 129 vulnerabilities, including exploited Qualcomm flaw CVE-2026-21385 and critical RCE CVE-2026-0006.
originalePart of the PlainSec briefing for 2026-03-05
Every edition of this story: Zero-day Qualcomm Sfruttato in Attacchi Su Chipset Android