Back Betanews Google patches scores of vulnerabilities with March Android Security Bulletin
Google has released its latest security update for Android, announcing in the March 2026 Android Security Bulletin that it has addressed a total of 129 vulnerabilities.
Included among these vulnerabilities is CVE-2026-21385, a zero-day affecting an open-source Qualcomm component. While the company has not shared much in the way of detail, it says that “there are indications that CVE-2026-21385 may be under limited, targeted exploitation”.
CVE-2026-21385 affects the display component of Android and has been assigned a severity rating of High. There are actually numerous Qualcomm components with issues that are addressed with this latest update, as Google explains :
These vulnerabilities affect Qualcomm components and are described in further detail in the appropriate Qualcomm security bulletin or security alert. The severity assessment of these issues is provided directly by Qualcomm.
Qualcomm closed-source components
These vulnerabilities affect Qualcomm closed-source components and are described in further detail in the appropriate Qualcomm security bulletin or security alert. The severity assessment of these issues is provided directly by Qualcomm.
The CVE-2026-21385 issue has a CVSS score of 7.8, and was first reported back in December. There are currently no details how it has been exploited and how widespread the issue is.
In its own security bulletin , Qualcomm refers to CVE-2026-21385 as an “Integer Overflow or Wraparound in Graphics”, describing it as “memory corruption while using alignments for memory allocation”.
The company also provides links to patches:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
