CVE-2026-21385
KEVmassMemory Corruption in Qualcomm Snapdragon Chipset Firmware Exploited in the Wild
CISA: Qualcomm Multiple Chipsets Memory Corruption Vulnerability
CVE-2026-21385 is a memory corruption flaw (CWE-190, integer overflow) in how firmware on a range of Qualcomm Snapdragon chipsets and Qualcomm smart-audio/display platforms handles alignment during memory allocation. It is triggered locally by low-privileged code that performs aligned memory allocations, allowing an attacker running on the device (for example, a malicious app or component) to corrupt memory. Successful exploitation yields high confidentiality, integrity, and availability impact — effectively kernel-level compromise or privilege escalation on the affected device. Affected devices include Android phones built on the listed Snapdragon SoCs (e.g., Snapdragon 429, 4 Gen 1/2, and several 8-series variants) plus Smart Audio 400 and Smart Display 200 platform firmware; Google confirmed it is being exploited in an Android component and shipped a fix in its March 2026 Android security bulletin. The flaw is actively exploited (added to CISA's KEV on 2026-03-03), though no public proof-of-concept is known and ransomware use is unknown.
What to do: Patch Android devices to the March 2026 Android security bulletin level (patch level 2026-03-01 or later) or the OEM's equivalent Qualcomm firmware update, prioritizing devices on the listed Snapdragon SoCs; check the installed patch level under Settings > Security > Android security update. Federal/managed environments should follow BOD 22-01 guidance per the CISA KEV entry, and owners of Smart Audio 400 / Smart Display 200-based products should obtain updated firmware from their OEM.
| Qualcomm SM7675P firmware | — |
| Qualcomm SM8475P firmware | — |
| Qualcomm SM8550P firmware | — |
| Qualcomm SM8635 firmware | — |
| Qualcomm SM8635P firmware | — |
| Qualcomm SM8650Q firmware | — |
| Qualcomm SM8750P firmware | — |
| Qualcomm Smart Audio 400 Platform firmware | — |
| Qualcomm Smart Display 200 Platform firmware | — |
| Qualcomm Snapdragon 4 Gen 1 Mobile Platform firmware | — |
| Qualcomm Snapdragon 4 Gen 2 Mobile Platform firmware | — |
| Qualcomm Snapdragon 429 Mobile Platform firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Memory corruption while using alignments for memory allocation.
- Affected
- Qualcomm Multiple Chipsets
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- qualcomm
- Products
- sm7675p firmware, sm8475p firmware, sm8550p firmware, sm8635 firmware, sm8635p firmware, sm8650q firmware, sm8750p firmware, smart audio 400 platform firmware, smart display 200 platform firmware, snapdragon 4 gen 1 mobile platform firmware, snapdragon 4 gen 2 mobile platform firmware, snapdragon 429 mobile platform firmware
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H