CVE-2026-21385 - Vulnerability Analysis
HighCVSS: 7.8Last Updated: March 4, 2026
Overview
Memory corruption while using alignments for memory allocation.
Severity & Score
References
- https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit
- https://source.android.com/docs/security/bulletin/2026/2026-03-01
- https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2026-bulletin.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21385
Social Media Activity(6 posts)
Google notifying Android user of high-severity vuln CVE-2026-21385 and March 2026 security update might work better if that link the "AI Mode" #slopgenerator did not link to December 2025 bulletin.
View original postThe exploitation activity against CVE-2026-21385, a high-severity memory corruption flaw, could be tied to commercial spyware or nation-state threat groups. https://www.darkreading.com/threat-intelligence/qualcomm-zero-day-exploited-targeted-android-attacks
View original post🚨 [CISA-2026:0303] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0303) CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise. ⚠️ CVE-2026-21385 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-21385) - Name: Qualcomm Multiple Chipsets Memory Corruption Vulnerability - Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. - Known To Be Used in Ransomware Campaigns? Unknown - Vendor: Qualcomm - Product: Multiple Chipsets - Notes: https://source.android.com/docs/security/bulletin/2026/2026-03-01 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21385 ⚠️ CVE-2026-22719 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-22719) - Name: Broadcom VMware Aria Operations Command Injection Vulnerability - Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. - Known To Be Used in Ransomware Campaigns? Unknown - Vendor: Broadcom - Product: VMware Aria Operations - Notes: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ; https://knowledge.broadcom.com/external/article/430349 ; https://nvd.nist.gov/vuln/detail/CVE-2026-22719 #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260303 #cisa20260303 #cve_2026_21385 #cve_2026_22719 #cve202621385 #cve202622719
View original postCVE ID: CVE-2026-21385 Vendor: Qualcomm Product: Multiple Chipsets Date Added: 2026-03-03 Notes: https://source.android.com/docs/security/bulletin/2026/2026-03-01 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21385 CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-21385
View original postAggiornamenti Android marzo 2026, corretta una zero-day già sfruttata: cosa fare subito Google ha rilasciato l’Android Security Bulletin di marzo 2026, il più corposo dell’anno: 129 vulnerabilità corrette di cui una, la CVE-2026-21385... 🔗️ [Cybersecurity360] https://link.is.it/AC1JZ9
View original postGoogle confirms that the Qualcomm Android vulnerability CVE-2026-21385 was exploited in real-world attacks. #CVE_2026_21385 https://securityaffairs.com/188823/security/android-devices-hit-by-exploited-qualcomm-flaw-cve-2026-21385.html
View original postGitHub Repositories(1 repo)
Related Resources
Details
- CVE ID
- CVE-2026-21385
- Severity
- High
- CVSS Score
- 7.8
- Status
- confirmed
- EPSS
- 34.1%
- Social Posts
- 6
CWE
- CWE-190
CVSS Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H