logo

Qualcomm Zero-Day Exploited in Targeted Android Attacks

ID: 58413a45-9bce-55f5-86b1-3cdd9b71ce3f

STIX ID: report--58413a45-9bce-55f5-86b1-3cdd9b71ce3f

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-03-03

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Google and Qualcomm disclosed two significant Android vulnerabilities: CVE-2026-21385 (a Qualcomm graphics kernel integer overflow with indications of limited, targeted exploitation) and CVE-2026-0047 (a critical local privilege escalation in Android's System component). Patches are available, CVE-2026-21385 was added to CISA's KEV catalog, but consumer exposure may persist due to OEM-dependent patch rollouts and the potential for these flaws to be leveraged in chained attacks or by commercial/nation-state actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.