Vulnerability record · CVE-2026-21385 · published 2 March 2026
CVE-2026-21385: Qualcomm chipset firmware memory corruption via alignment integer overflow
Qualcomm · Sm7675p Firmware
A memory corruption flaw in Qualcomm chipset firmware arises from an integer overflow when alignments are used for memory allocation (CWE-190). It affects a broad set of Snapdragon mobile, smart audio and smart display platforms, and CISA added it to the Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.
Description
Memory corruption while using alignments for memory allocation.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is a high-severity local memory corruption issue with confirmed inclusion in CISA KEV, though EPSS is low and no ransomware use is documented.
What it is
A memory corruption flaw in Qualcomm chipset firmware arises from an integer overflow when alignments are used for memory allocation (CWE-190). It affects a broad set of Snapdragon mobile, smart audio and smart display platforms, and CISA added it to the Known Exploited Vulnerabilities catalog, so it warrants prompt remediation.
Impact
An attacker who can run code locally on the device can corrupt memory and potentially gain code execution or escalate privileges in the affected firmware context, with high impact to confidentiality, integrity and availability.
Attack surface
The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the flaw is reached by a local actor already able to execute code on the device rather than remotely over a network.
Exploitation
CISA added this CVE to the KEV catalog on 2026-03-03 with a remediation due date of 2026-03-24, indicating known exploitation; EPSS is low at roughly 1.3 percent for the next 30 days, and no ransomware campaign use is documented.
What to do
- Apply the Qualcomm March 2026 security bulletin firmware updates for all listed chipsets as the first action.
- Apply the corresponding Android March 2026 security bulletin updates on affected devices.
- If vendor mitigations are unavailable, follow CISA BOD 22-01 guidance or discontinue use of the affected product per the KEV required action.
- Track the 2026-03-24 KEV due date and verify remediation across all affected Snapdragon, smart audio and smart display platforms.
- Limit local code execution and untrusted app installation on affected devices to reduce exposure to the local attack vector.
Detection
- Monitor for anomalous crashes or memory corruption indicators in firmware and kernel logs on affected Qualcomm-based devices.
- Audit devices for the presence of the March 2026 Qualcomm and Android security patch levels.
- Hunt for unexpected local privilege escalation or code execution activity originating from low-privileged local processes on affected platforms.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-21385 to the Known Exploited Vulnerabilities catalog on 3 March 2026 as "Qualcomm Multiple Chipsets Memory Corruption Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 March 2026.
Affected products
150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2026-bulletin.html | PatchVendor Advisory |
| https://source.android.com/docs/security/bulletin/2026/2026-03-01 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21385 | US Government Resource |
Track CVE-2026-21385 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-21385), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.