A Qualcomm zero-day vulnerability (CVE-2026-21385) affecting the graphics kernel across a wide range of chipsets is being actively exploited in limited, targeted Android attacks. The high-severity memory corruption flaw (CVSS 7.8) has been added to CISA's Known Exploited Vulnerabilities catalog. Security experts suggest the exploitation pattern is consistent with commercial spyware or nation-state activity, drawing parallels to CVE-2024-43047 which was later linked to commercial spyware. A second notable vulnerability, CVE-2026-0047, is a critical local privilege escalation flaw in Android's System component that hasn't yet been exploited but could be used in chained attacks. Patches are available but Android's OEM-dependent patching ecosystem means consumer devices may remain vulnerable for extended periods.