Junglewise Threat Intelligence

CVE-2026-21385: Qualcomm Multiple Chipsets memory corruption in memory allocation

CVE-2026-21385 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2026-03-03

Technologies: Qualcomm Multiple Chipsets. Vendors: Qualcomm.

Executive brief

A security vulnerability exists in the firmware of several Qualcomm chipsets used in mobile devices. This flaw could allow a malicious application already on the device to gain deeper access to the system's memory, potentially leading to a full device compromise or data theft. This issue is known to have been exploited in the wild, making immediate updates critical for affected hardware.

Technical details

A memory corruption vulnerability exists in multiple Qualcomm chipsets due to an integer overflow (CWE-190) occurring during memory allocation alignment processes. An attacker with local access and low privileges can exploit this flaw to trigger memory corruption, potentially leading to unauthorized code execution or a complete system crash. The vulnerability has been confirmed as exploited in the wild and is addressed in the March 2026 Qualcomm security bulletin. The attack vector is local, requiring no user interaction to succeed once a malicious process is running on the system.

Affected products

  • Qualcomm SM7675P Firmware
  • Qualcomm SM8475P Firmware

Timeline

  • 2026-03-03: disclosed
  • 2026-03-03: advisory
  • 2026-03-03: kev added: Added to CISA KEV catalog
  • 2026-03-03: exploited

Related threats