Vulnerabilities · 196 days ago
Qualcomm Display Zero-Day Actively Exploited (CVE-2026-21385) Google disclosed a memory‑corruption zero‑day (CVE‑2026‑21385) in an open‑source Qualcomm display component affecting 234 chipsets; Google marked it as actively exploited. Qualcomm issued fixes to OEMs in January — apply device OEM February 2026 Android security updates immediately.
NVD KEV
Known exploited · CISA KEV
CVSS 7.8 HIGH: memory corruption while using alignments for memory allocation.
CISA federal remediation date Mar 24
Timeline Sources 6 sources covering this story
Dark Reading Mar 3
Qualcomm Zero-Day Exploited in Targeted Android Attacks
The exploitation of CVE-2026-21385, a high-severity memory corruption flaw, could be tied to commercial spyware or nation-state threat groups.
SecurityWeek Mar 3
Android Update Patches Exploited Qualcomm Zero-Day
An integer overflow or wraparound in the Qualcomm graphics component, the bug leads to memory corruption.
The Hacker News Mar 3
Google Confirms CVE-2026-21385 in Qualcomm Android Component Exploited
Google’s March 2026 Android update patches 129 vulnerabilities, including exploited Qualcomm flaw CVE-2026-21385 and critical RCE CVE-2026-0006.
Help Net Security Mar 3
Android's March 2026 security patch fixes over 100 flaws, one under targeted exploitation - Help Net Security
The Android March 2026 security patch fixes flaws across Framework, System, kernel, chipsets, with a CVE confirmed under active exploitation.
BleepingComputer Mar 3
Android gets patches for Qualcomm zero-day exploited in attacks
Google has released security updates to patch 129 Android security vulnerabilities, including an actively exploited zero-day flaw in a Qualcomm display component.
CyberScoop Mar 2
Google addresses actively exploited Qualcomm zero-day in fresh batch of 129 Android vulnerabilities
The company’s latest security update contains the highest number of Android vulnerabilities patched in a single month since April 2018.
Entities Part of the PlainSec briefing for 2026-03-07
Editions Related stories
Vulnerabilities · 196 days ago
Qualcomm Display Zero-Day Actively Exploited (CVE-2026-21385) Google disclosed a memory‑corruption zero‑day (CVE‑2026‑21385) in an open‑source Qualcomm display component affecting 234 chipsets; Google marked it as actively exploited. Qualcomm issued fixes to OEMs in January — apply device OEM February 2026 Android security updates immediately.
NVD KEV
Known exploited · CISA KEV
CVSS 7.8 HIGH: memory corruption while using alignments for memory allocation.
CISA federal remediation date Mar 24
Timeline Sources 6 sources covering this story
Dark Reading Mar 3
Qualcomm Zero-Day Exploited in Targeted Android Attacks
The exploitation of CVE-2026-21385, a high-severity memory corruption flaw, could be tied to commercial spyware or nation-state threat groups.
SecurityWeek Mar 3
Android Update Patches Exploited Qualcomm Zero-Day
An integer overflow or wraparound in the Qualcomm graphics component, the bug leads to memory corruption.
The Hacker News Mar 3
Google Confirms CVE-2026-21385 in Qualcomm Android Component Exploited
Google’s March 2026 Android update patches 129 vulnerabilities, including exploited Qualcomm flaw CVE-2026-21385 and critical RCE CVE-2026-0006.
Help Net Security Mar 3
Android's March 2026 security patch fixes over 100 flaws, one under targeted exploitation - Help Net Security
The Android March 2026 security patch fixes flaws across Framework, System, kernel, chipsets, with a CVE confirmed under active exploitation.
BleepingComputer Mar 3
Android gets patches for Qualcomm zero-day exploited in attacks
Google has released security updates to patch 129 Android security vulnerabilities, including an actively exploited zero-day flaw in a Qualcomm display component.
CyberScoop Mar 2
Google addresses actively exploited Qualcomm zero-day in fresh batch of 129 Android vulnerabilities
The company’s latest security update contains the highest number of Android vulnerabilities patched in a single month since April 2018.
Entities Part of the PlainSec briefing for 2026-03-07
Editions Related stories