CVE-2026-21385 is a critical memory corruption vulnerability, specifically an integer overflow in Qualcomm's GPU display driver, affecting billions of Android devices. With a CVSS score of 7.8 HIGH, this flaw allows a local attacker with low privileges to achieve kernel code execution, leading to complete device compromise without user interaction. This zero-day vulnerability is actively exploited in targeted attacks, as confirmed by its inclusion in CISA's KEV catalog and extensive media coverage. While public exploit code is not readily available, significant community discussion and research highlight its severity and ongoing threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:sm7675p_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:sm8475p_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:sm8550p_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:sm8635_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:sm8635p_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.