<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Qualcomm Zero-Day Exploited in Targeted Android Attacks

Qualcomm kernel flaw CVE-2026-21385 exploited in targeted Android attacks, requiring urgent patches to prevent rapid spread.
Content Team

A Qualcomm graphics kernel vulnerability (CVE-2026-21385) is being exploited in "limited, targeted" attacks against Android devices. Google's March security bulletin flagged this high-severity flaw, which affects multiple chipsets and earned a 7.8 CVSS score.

Security experts believe the "limited, targeted" language suggests nation-state actors or commercial spyware vendors are behind the attacks, similar to previous Qualcomm zero-days linked to surveillance tools. The vulnerability requires local access and causes memory corruption during allocation.

Another critical flaw (CVE-2026-0047) allows privilege escalation without user interaction, though it needs existing device access. Patches are available through Qualcomm and Android's open source project, but users must wait for device manufacturers to deploy updates—a delay that matters when exploits spread rapidly.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo