CVE detail
CVE-2026-21385
Memory corruption while using alignments for memory allocation.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- Critical Android vulnerability CVE-2026-0073 fixed by GoogleSecurity Affairs
Google patched a critical Android flaw (CVE‑2026‑0073) that lets attackers run code remotely without user action. Google released a security update for Android to address a critical remote code execution flaw, tracked as CVE‑2026‑0073, in the System component. The bug allowed attackers to run code as the shell user without needing extra permissions, or any […]
newssecurityaffairs.comMay 5, 2026, 2:06 PM - 9th March – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 9th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES AkzoNobel, a Netherlands-based global paint manufacturer, has confirmed a cyberattack affecting one of its United States sites. The company said the intrusion was contained, while the Anubis ransomware group claimed it stole […]
vendorresearch.checkpoint.comMar 9, 2026, 4:36 PM A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. FBI probing intrusion into a system managing sensitive surveillance information Reading White House President Trump’s Cyber […]
newssecurityaffairs.comMar 8, 2026, 8:46 AM- High-severity Qualcomm bug hits Android devices in targeted attacksMalwarebytes Labs
Google has patched 129 Android vulnerabilities, including an actively exploited flaw in a widely used Qualcomm component.
newswww.malwarebytes.comMar 4, 2026, 12:33 PM - U.S. CISA adds Qualcomm and Broadcom VMware Aria Operations flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Qualcomm and Broadcom VMware Aria Operations flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Google Chromium CSS, Microsoft Windows, TeamT5 ThreatSonar Anti-Ransomware, and Zimbra flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: In […]
newssecurityaffairs.comMar 4, 2026, 8:56 AM An integer overflow or wraparound in the Qualcomm graphics component, the bug leads to memory corruption.
newswww.securityweek.comMar 3, 2026, 12:41 PM- Android devices hit by exploited Qualcomm flaw CVE-2026-21385Security Affairs
Google confirms that the Qualcomm Android vulnerability CVE-2026-21385 was exploited in real-world attacks. Google has confirmed that CVE-2026-21385 (CVSS score of 7.8), a high-severity vulnerability affecting an open-source Qualcomm component used in Android devices, has been actively exploited. “There are indications that CVE-2026-21385 may be under limited, targeted exploitation.” reads Google’s advisory. The flaw is […]
newssecurityaffairs.comMar 3, 2026, 10:03 AM - Android’s March 2026 security patch fixes over 100 flaws, one under targeted exploitationHelp Net Security
The Android March 2026 security patch addresses vulnerabilities across dozens of components and includes one CVE confirmed under active exploitation. Devices running a patch level of 2026-03-05 or later receive fixes for all disclosed issues. Android March 2026 security patch includes one CVE under active exploitation The bulletin notes indications that CVE-2026-21385 may be under limited, targeted exploitation. The flaw resides in the Qualcomm Display component and is rated High severity. Organizations running devices with … More →
newswww.helpnetsecurity.comMar 3, 2026, 9:38 AM No excerpt available.
Mitigationwww.cisa.govMar 2, 2026, 5:16 PM- https://source.android.com/docs/security/bulletin/2026/2026-03-01source.android.com
No excerpt available.
Vendor Advisorysource.android.comMar 2, 2026, 5:16 PM - https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2026-bulletin.htmldocs.qualcomm.com
No excerpt available.
Vendor Advisorydocs.qualcomm.comMar 2, 2026, 5:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-24090CVSS 7.1 · High
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
- CVE-2024-45549CVSS 7.7 · High
Information disclosure while creating MQ channels.
- CVE-2025-47402CVSS 6.5 · Medium
Transient DOS when processing a received frame with an excessively large authentication information element.
- CVE-2025-47370CVSS 6.5 · Medium
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
- CVE-2025-27052CVSS 7.8 · High
Memory corruption while processing data packets in diag received from Unix clients.
- CVE-2024-53014CVSS 7.8 · High
Memory corruption may occur while validating ports and channels in Audio driver.