Skip to content
CISA Warns Qualcomm Chipsets Memory Corruption Vulnerability Is Actively Exploited in Attacks

CISA Warns Qualcomm Chipsets Memory Corruption Vulnerability Is Actively Exploited in Attacks

Gbhackers March 4, 2026

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Qualcomm chipset vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on March 3, 2026, confirming active exploitation in the wild.

The flaw, tracked as CVE-2026-21385, affects multiple Qualcomm chipsets and introduces a serious memory corruption risk that attackers can leverage to compromise affected devices.

The vulnerability stems from an integer overflow condition (CWE-190) that occurs during memory allocation alignment operations across multiple Qualcomm chipsets.

When a chipset processes specific memory alignment requests, improper validation allows integer values to overflow, corrupting adjacent memory regions.

This kind of flaw can allow threat actors to execute arbitrary code, escalate privileges, or destabilise targeted systems, making it especially dangerous in mobile, embedded, and IoT environments where Qualcomm chipsets are widely deployed.

Qualcomm processors power hundreds of millions of Android smartphones, tablets, automotive systems, and connected devices globally, which significantly broadens the attack surface for this vulnerability.

CISA’s inclusion of this flaw in the KEV catalog confirms that threat actors are actively exploiting CVE-2026-21385 in real-world attacks.

While ransomware campaign involvement remains unknown at this stage, memory corruption vulnerabilities of this class are frequently weaponized for privilege escalation, remote code execution chains, and persistent device compromise.

The broad deployment of Qualcomm chipsets makes this an attractive target for both state- actors and cybercriminal groups.

CISA has mandated that all Federal Civilian Executive Branch (FCEB) agencies remediate this vulnerability by March 24, 2026, in line with Binding Operational Directive (BOD) 22-01.

CISA recommends all organizations take the following steps immediately:

Organizations relying on Qualcomm-powered infrastructure should treat this as a high-priority remediation item given the active exploitation status confirmed by CISA.

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Iran‑nexus APT group “Dust Specter” is targeting Iraqi government officials with AI‑assisted custom .NET malware,…

Security researchers at Zero Science Lab have disclosed a critical vulnerability in Honeywell's Trend IQ4xx…

Cyberattacks are shifting from “breaking in” to simply “logging in,” with AI now automating high-speed…

Security researchers at Zenity Labs disclosed a critical flaw in Perplexity’s Comet “agentic” browser that…

VoidLink marks a turning point in how adversaries target Kubernetes and AI workloads, signaling a…

A dramatic escalation in Middle Eastern tensions began last week with Operation Lion's Roar, a…

Extracted Entities

APT Groups (1)

Attack Types (1)

Campaigns (1)

Industries (1)

Platforms (1)