Google Warns of Actively Exploited Qualcomm Zero-Day in Android Devices
Mar 3, 2026 // 12:19 - Norina Velotta


Google has confirmed that a high-severity security flaw, CVE-2026-21385 (CVSS score 7.8), in an open-source Qualcomm graphics component is being exploited in the wild. 

The vulnerability was disclosed as part of the March 2026 Android Security Bulletin, which addresses 129 vulnerabilities in total. 

Vulnerability Details

  • Type: An integer overflow or wraparound leading to a buffer over-read.
  • Impact: Local attackers can exploit the flaw to trigger memory corruption, potentially leading to unauthorized data access or privilege escalation.
  • Affected Scope: Approximately 234-235 Qualcomm chipsets are impacted.
  • Exploitation Status: Google indicated there are signs of limited, targeted exploitation, though specific details regarding the attackers or methods have not been released. 

Timeline & Mitigation

  • Reported: Google’s Android Security team first reported the issue to Qualcomm on December 18, 2025.
  • Notification: Qualcomm notified its customers (OEMs) of the defect on February 2, 2026.
  • Action Required: Users are urged to check for system updates and install the March 2026 security patch as soon as it is provided by their device manufacturer.

#actively  #android  #devices  #exploited  #google  #news  #qualcomm  #warns  #zero-day   —   News