• News/
  • https://www.bleepingcomputer.com/news/security/google-patches-android-zero-day-actively-exploited-in-attacks/

Android gets patches for Qualcomm zero-day exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 3, 2026
·
Updated

Google has released security updates to patch 129 Android security vulnerabilities, including an actively exploited zero-day flaw in a Qualcomm display component. "There are indications that CVE-2026-21385 may be under limited, targeted exploitation," the company said on Monday in its March 2025 Android Security Bulletin. While Google didn't provide any further information on the attacks currently targeting this vulnerability, Qualcomm revealed in a separate security advisory issued on February 3 that the flaw is an integer overflow or wraparound in the Graphics subcomponent that local attackers can exploit to trigger memory corruption. Qualcomm says it was alerted to this high-severity vulnerability on December 18 by Google's Android Security team, and it notified customers on February 2. According to its February advisory, which has yet to flag CVE-2026-21385 as exploited in attacks, the security flaw affects 235 Qualcomm chipsets. "We commend the researchers from Google’s Threat Analysis Group for using coordinated disclosure practices," a Qualcomm spokesperson told BleepingComputer. "Regarding their GPU-related research, fixes were made available to our customers in January 2026. We encourage end users to apply security updates as they become available from device makers." With this month's Android security updates, Google fixed 10 critical security vulnerabilities in the System, Framework, and Kernel components that attackers exploit to gain remote code execution, eleva...

Read full article

Affected Software

2 affected components
Qualcomm Graphics
Google Android>=March 2025
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Google's release of security updates for Android, specifically addressing a zero-day vulnerability in a Qualcomm display component.

2

What security implications are discussed in the article?

The article highlights the presence of an actively exploited zero-day flaw, indicating potential risks to users due to limited, targeted exploitation.

3

What products or software are affected by this security update?

The security updates affect Qualcomm Graphics and Google Android software.

4

What is the identifier for the zero-day vulnerability mentioned?

The zero-day vulnerability is identified as CVE-2026-21385.

5

When were the security updates released?

The security updates were released on March 3, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203