Google released the March 2026 Android Security Bulletin, issuing fixes for 129 vulnerabilities across the Android ecosystem and shipping two patch levels (2026-03-01 and 2026-03-05) to help OEMs stage platform and hardware-specific updates. The most urgent issue is CVE-2026-21385, a high-severity, actively exploited zero-day in an open-source Qualcomm display component used in Android devices with affected Qualcomm/Snapdragon chipsets.
Reporting indicates CVE-2026-21385 is a memory-corruption flaw caused by an integer overflow/wraparound condition that can lead to memory corruption during allocation/alignment in display drivers; successful exploitation could enable device compromise (e.g., arbitrary code execution and/or privilege escalation) and bypass security boundaries. Google and Qualcomm both acknowledged limited, targeted exploitation in the wild, and one account attributes discovery/confirmation of exploitation to Google’s Threat Analysis Group (TAG); devices not updated to at least patch level 2026-03-05 remain exposed, making rapid patch deployment and user update compliance the primary risk-reduction actions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Google updated the March 2026 Android Security Bulletin to add AOSP source patch links, following its notice that source code patches would be released within 48 hours of initial publication. The bulletin update was recorded on March 6, 2026.
CISA added CVE-2026-21385 to its Known Exploited Vulnerabilities catalog after Google's disclosure of active exploitation. The agency set a remediation deadline of 2026-03-24 for U.S. Federal Civilian Executive Branch agencies.
Google made the March 2026 Android fixes available, with Pixel devices receiving updates immediately and OEM partners able to roll out patches on their own schedules. The split patch levels were intended to help vendors deploy fixes across different device models and component sets.
In the March bulletin, Google disclosed that CVE-2026-21385, a high-severity Qualcomm open-source display/graphics flaw, had seen limited, targeted exploitation before public disclosure. The bug was described as an integer overflow/wraparound or related memory-safety issue leading to memory corruption.
Google released the March 2026 Android Security Bulletin with patch levels 2026-03-01 and 2026-03-05, addressing 129 vulnerabilities across Android platform, kernel, and vendor components. The bulletin said devices on patch level 2026-03-05 or later are protected against all listed issues.
Qualcomm informed customers in early February 2026 about CVE-2026-21385, a memory-corruption issue affecting Qualcomm display/graphics components used in Android devices. Reports said the flaw impacts a large number of Qualcomm chipsets.
Google's Android security team/Threat Analysis Group reported the Qualcomm display/graphics flaw CVE-2026-21385 to Qualcomm in December 2025, starting the vendor remediation process. Multiple reports place this notification on or around December 18, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcethecyberthrone.in
Open sourcedarkreading.com
Open sourcesource.android.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.