2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

Google: CVE-2026-21385 in Qualcomm Graphics Component Observed in Targeted Exploits


Google has revealed that attackers have taken advantage of a serious security vulnerability in an open-source Qualcomm component bundled with Android devices. The issue affects the Graphics portion of the code and has been classified as high severity.

The defect is tracked as CVE-2026-21385 and carries a CVSS score of 7.8. According to Qualcomm, the bug manifests as a buffer over-read stemming from an integer overflow. In practical terms, the problem can cause memory corruption when user-provided data is appended without verifying remaining buffer capacity.

Qualcomm says the bug was reported via Google’s Android Security team on December 18, 2025, and customers were informed of the issue on February 2, 2026. While technical specifics about how threat actors are exploiting the vulnerability have not been released, Google’s Android security bulletin states there are signs the flaw “may be under limited, targeted exploitation.”

Google’s March 2026 security update addresses a total of 129 vulnerabilities. Among those is a critical System component vulnerability, CVE-2026-0006, which Google warns could allow remote code execution without needing extra privileges or any user interaction.

For context, Google fixed a single Android vulnerability in January 2026 and reported none in February 2026 before this March tranche of patches.

Other notable critical fixes in the March release include:

• A Framework privilege-escalation issue: CVE-2026-0047
• A denial-of-service bug in the System component: CVE-2025-48631
• Seven Kernel privilege-escalation defects: CVE-2024-43859, CVE-2026-0037, CVE-2026-0038, CVE-2026-0027, CVE-2026-0028, CVE-2026-0030, CVE-2026-0031

The bulletin provides two patch levels – 2026-03-01 and 2026-03-05 – so Android partners can roll out fixes at different cadences depending on device and supply-chain requirements. The later patch level incorporates Kernel fixes as well as updates originating from vendors such as Arm, Imagination Technologies, MediaTek, Qualcomm, and Unisoc.

First published on March 3, 2026.
Last updated on July 15, 2026.