Google addresses actively exploited Qualcomm zero-day in fresh batch of 129 Android vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21385 | Memory Corruption in Qualcomm Snapdragon Chipset Firmware Exploited in the Wild CVE-2026-21385 is a memory corruption flaw (CWE-190, integer overflow) in how firmware on a range of Qualcomm Snapdragon chipsets and Qualcomm smart-audio/display platforms handles alignment during memory allocation. It is triggered locally by low-privileged code that performs aligned memory allocations, allowing an attacker running on the device (for example, a malicious app or component) to corrupt memory. Successful exploitation yields high confidentiality, integrity, and availability impact — effectively kernel-level compromise or privilege escalation on the affected device. Affected devices include Android phones built on the listed Snapdragon SoCs (e.g., Snapdragon 429, 4 Gen 1/2, and several 8-series variants) plus Smart Audio 400 and Smart Display 200 platform firmware; Google confirmed it is being exploited in an Android component and shipped a fix in its March 2026 Android security bulletin. The flaw is actively exploited (added to CISA's KEV on 2026-03-03), though no public proof-of-concept is known and ransomware use is unknown. Do: Patch Android devices to the March 2026 Android security bulletin level (patch level 2026-03-01 or later) or the OEM's equivalent Qualcomm firmware update, prioritizing devices on the listed Snapdragon SoCs; check the installed patch level under Settings > Security > Android security update. Federal/managed environments should follow BOD 22-01 guidance per the CISA KEV entry, and owners of Smart Audio 400 / Smart Display 200-based products should obtain updated firmware from their OEM. | 7.8 | 1% | KEV |
| masshundreds of millions of devices (listed Snapdragon SoCs span flagship 8-series through entry-level 4-series Android phones) |
Full article767 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The company’s latest security update contains the highest number of Android vulnerabilities patched in a single month since April 2018.
Listen to this article
0:00
Learn more.
Google disclosed one actively exploited zero-day vulnerability Monday, warning that the high-severity defect affecting an open-source Qualcomm display component for Android devices “may be under limited, targeted exploitation.”
The memory-corruption vulnerability — CVE-2026-21385 — which Google’s Android security team reported to Qualcomm Dec. 18, affects 234 chipsets, Qualcomm said in a security bulletin. Qualcomm said it notified customers of the vulnerability Feb. 2.
Qualcomm declined to say when the earliest known instance of exploitation occurred, how many victims have been directly impacted, and what occurred during the 10-week period between the reporting and public disclosure of the vulnerability.
“We commend the researchers from Google’s Threat Analysis Group for using coordinated disclosure practices,” a Qualcomm spokesperson told CyberScoop. “Fixes were made available to our customers in January 2026. We encourage end users to apply security updates as they become available from device makers.”
A Google spokesperson said Qualcomm marked the vulnerability as exploited. “We don’t have any info or access to the exploit reports,” the spokesperson added.
Google addressed 129 defects in its monthly security update for Android devices, reflecting a surge in vulnerability disclosures from the vendor. The company’s latest security update contains the highest number of Android vulnerabilities patched in a single month since April 2018.
Google’s public vulnerability disclosure and reporting program for Android has been uneven. The company typically issued dozens of security patches each month, but that cadence has shifted to a more occasional routine.
So far this year, Google addressed one Android vulnerability in January and none in February. There were occasional lulls last year as well when Google reported no vulnerabilities in July and October, six in August and two vulnerabilities in November. Yet, disclosures for 2025 peaked with 120 defects in September and rebounded again in December with 107 vulnerabilities, including two zero-days.
Google previously responded to questions about dips in the amount of vulnerabilities it discloses each month, noting that it remains focused on defects that pose the greatest danger.
“Android stops most vulnerability exploitation at the source with extensive platform hardening, like our use of the memory-safe language Rust and advanced anti-exploitation protections,” a Google spokesperson said in December. “Android and Pixel continuously address known security vulnerabilities and prioritize fixing and patching the highest-risk ones first.”
The Android security bulletin for March includes two patch levels — 2026-03-01 and 2026-03-05 — allowing Android partners to address common vulnerabilities on different devices. Android device manufacturers release security patches on their own schedule after they’ve customized operating system updates for their specific hardware.
The primary security update contains 63 vulnerabilities, including 32 in the framework, 19 in the system and 12 affecting Google Play. Nearly half of those vulnerabilities have CVE identifiers from 2025.
The second patch addresses 66 vulnerabilities, including 15 vulnerabilities affecting the kernel, one Arm component defect, seven Imagination Technologies flaws and seven vulnerabilities in Unisoc components.
The second patch level also contains fixes for eight vulnerabilities in closed-source Qualcomm components and seven high-severity defects in open-source Qualcomm components, including CVE-2026-21385.
Google said source code for all vulnerabilities addressed in this month’s Android security bulletin will be released to the Android Open Source Project repository by Wednesday.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-security-update-march-2026/