A Qualcomm zero-day vulnerability (CVE-2026-21385) affecting the graphics kernel across a wide range of chipsets is being actively exploited in limited, targeted Android attacks. The high-severity memory corruption flaw (CVSS 7.8) has been added to CISA's Known Exploited Vulnerabilities catalog. Security experts suggest the exploitation pattern is consistent with commercial spyware or nation-state activity, drawing parallels to CVE-2024-43047 which was later linked to commercial spyware. A second notable vulnerability, CVE-2026-0047, is a critical local privilege escalation flaw in Android's System component that hasn't yet been exploited but could be used in chained attacks. Patches are available but Android's OEM-dependent patching ecosystem means consumer devices may remain vulnerable for extended periods.

4m read timeFrom darkreading.com
Post cover image
Table of contents
Possible Spyware Attack?The Complexities of Patching Android Flaws
188 Impressions