Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityembedded-device-vulnerabilitywidely-deployed-product-advisoryopen-source-dependency-vulnerability

Google March Android Security Bulletin Patches 129 Flaws Including Actively Exploited Qualcomm Display Zero-Day

Updated 3mo agoFirst seen Mar 3, 202610 sources

Google released the March 2026 Android Security Bulletin, issuing fixes for 129 vulnerabilities across the Android ecosystem and shipping two patch levels (2026-03-01 and 2026-03-05) to help OEMs stage platform and hardware-specific updates. The most urgent issue is CVE-2026-21385, a high-severity, actively exploited zero-day in an open-source Qualcomm display component used in Android devices with affected Qualcomm/Snapdragon chipsets.

Reporting indicates CVE-2026-21385 is a memory-corruption flaw caused by an integer overflow/wraparound condition that can lead to memory corruption during allocation/alignment in display drivers; successful exploitation could enable device compromise (e.g., arbitrary code execution and/or privilege escalation) and bypass security boundaries. Google and Qualcomm both acknowledged limited, targeted exploitation in the wild, and one account attributes discovery/confirmation of exploitation to Google’s Threat Analysis Group (TAG); devices not updated to at least patch level 2026-03-05 remain exposed, making rapid patch deployment and user update compliance the primary risk-reduction actions.

Share:
Google March Android Security Bulletin Patches 129 Flaws Including Actively Exploited Qualcomm Display Zero-Day
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Mar 6, 20264mo ago

Google publishes AOSP patch links in bulletin update

Google updated the March 2026 Android Security Bulletin to add AOSP source patch links, following its notice that source code patches would be released within 48 hours of initial publication. The bulletin update was recorded on March 6, 2026.

Mar 3, 20264mo ago

CISA adds CVE-2026-21385 to the KEV catalog

CISA added CVE-2026-21385 to its Known Exploited Vulnerabilities catalog after Google's disclosure of active exploitation. The agency set a remediation deadline of 2026-03-24 for U.S. Federal Civilian Executive Branch agencies.

Mar 2, 20264mo ago

March Android patches begin shipping to Pixel and partners

Google made the March 2026 Android fixes available, with Pixel devices receiving updates immediately and OEM partners able to roll out patches on their own schedules. The split patch levels were intended to help vendors deploy fixes across different device models and component sets.

Google discloses in-the-wild exploitation of CVE-2026-21385

In the March bulletin, Google disclosed that CVE-2026-21385, a high-severity Qualcomm open-source display/graphics flaw, had seen limited, targeted exploitation before public disclosure. The bug was described as an integer overflow/wraparound or related memory-safety issue leading to memory corruption.

Google publishes March 2026 Android Security Bulletin

Google released the March 2026 Android Security Bulletin with patch levels 2026-03-01 and 2026-03-05, addressing 129 vulnerabilities across Android platform, kernel, and vendor components. The bulletin said devices on patch level 2026-03-05 or later are protected against all listed issues.

Feb 1, 20265mo ago

Qualcomm notifies customers about the CVE-2026-21385 flaw

Qualcomm informed customers in early February 2026 about CVE-2026-21385, a memory-corruption issue affecting Qualcomm display/graphics components used in Android devices. Reports said the flaw impacts a large number of Qualcomm chipsets.

Dec 18, 20256mo ago

Google privately reports CVE-2026-21385 to Qualcomm

Google's Android security team/Threat Analysis Group reported the Qualcomm display/graphics flaw CVE-2026-21385 to Qualcomm in December 2025, starting the vendor remediation process. Multiple reports place this notification on or around December 18, 2025.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

36 LINKEDOpen in app
Affected products
2 linked
AndroidAndroid
Organizations
16 linked
QualcommGoogleImagination TechnologiesArmUnisocMediaTekSamsung ElectronicsBleepingComputerNokiaHuawei TechnologiesLG ElectronicsJamfAmnesty InternationalMotorolaSecurity AffairsOnePlus Technology (Shenzhen) Co., Ltd.
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.