Qualcomm Discloses Exploited Graphics Flaw CVE-2026-21385
Qualcomm N, 5775, Morehouse Drive, Barnes Canyon, Sorrento Mesa, San Diego, San Diego County, California, 92121, United States
Qualcomm
CONFIRMEDDate confidence: CONFIRMEDStated as firmHow firmly the source words the date: confirmed, scheduled, estimated, delayed or unverified.Show all CONFIRMED pins85% CONFIDENCEOverall confidence: 85%How well the pin's source and references back up its dates.Weighted average of how firmly 6 references, the source included, support the pin's start and end times; a reference counts half as much for every 180 days older than the newestShow all pins at 75% confidence or betterAndroid's[5] March 2026 bulletin is 'Published March 2, 2026' and says 'There are indications that CVE-2026-21385 may be under limited, targeted exploitation'; SecurityWeek[4] says Qualcomm[1] 'disclosed the security defect on Monday'.
Qualcomm and Google disclosed a memory-corruption bug in an open-source Qualcomm graphics component, affecting more than 230 chipsets, that 'may be under limited, targeted exploitation'.