- Start
- Mar 2, 202690% CONFIDENCEfrom the source
Qualcomm Discloses Exploited Graphics Flaw CVE-2026-21385
- On Monday 2 March 2026 Qualcomm's March bulletin and Google's Android security bulletin disclosed CVE-2026-21385, with Google warning 'There are indications that CVE-2026-21385 may be under limited, targeted exploitation'[1][5].
- The bug is an integer overflow in an open-source Qualcomm graphics/display component that corrupts memory 'while using alignments for memory allocation'; it is rated High, CVSS 7.8, and affects more than 230 Qualcomm chipsets[2][4][6].
- Google's Android security team reported it to Qualcomm on 18 December 2025; Qualcomm notified customers on 2 February, credited Google's Threat Analysis Group, and declined to say when exploitation began or how many people were targeted[6].
- The fix ships at Android's 2026-03-05 patch level, part of a March update covering 129 vulnerabilities, the most in a month since April 2018[6].
- CISA added the flaw to its Known Exploited Vulnerabilities catalog on 3 March 2026, giving federal agencies until 24 March to patch[3].
References 685% CONFIDENCE
The first entry is always the pin's source. Overall confidence is a weighted average of how firmly each reference supports the start and end times used above; a reference counts half as much for every 180 days older than the newest.
- [1]90%docs.qualcomm.com/product/publicresources/securitybulletin/march-2026-bulletin.htmldocs.qualcomm.com· Posted Sep 25, 2026· Starts Mar 2, 2026 ✓· 31% of score
Android's[5] March 2026 bulletin is 'Published March 2, 2026' and says 'There are indications that CVE-2026-21385 may be under limited, targeted exploitation'; SecurityWeek[4] says Qualcomm 'disclosed the security defect on Monday'.
- [2]75%High-severity Qualcomm bug hits Android devices in targeted attacksmalwarebytes.com· Published Mar 4, 2026· 14% of score
Explains that an attacker needs a local foothold such as a malicious app, and that phones at patch level 2026-03-05 or later are fixed.[1]
- [3]88%CISA Known Exploited Vulnerabilities Catalog: CVE-2026-21385cisa.gov· Published Mar 3, 2026· 14% of score
'Qualcomm[1] Multiple Chipsets Memory Corruption Vulnerability', added 3 March 2026 with a 24 March 2026 due date.
- [4]80%Android Update Patches Exploited Qualcomm Zero-Daysecurityweek.com· Published Mar 3, 2026· 14% of score
CVSS 7.8 integer overflow or wraparound in the graphics component of over 200 Qualcomm[1] chipsets, leading to memory corruption while using alignments for memory allocation.
- [5]88%Android Security Bulletin - March 2026source.android.com· Published Mar 2, 2026· 14% of score
Google's bulletin, published 2 March 2026: 'There are indications that CVE-2026-21385 may be under limited, targeted exploitation'; a High-severity Qualcomm[1] Display issue (QC-CR#4387106), fixed at the 2026-03-05 patch level.
Suggest a correction
Something missing or wrong? Say it in your own words: a link that backs this pin up, a different start or end date and why, or a fact it lacks or gets wrong. The AI checks it against this pin's sources, searches for better ones, and adds any page that backs you up. The pin's own sources still count most.