Cyber Security News

CISA warns of Qualcomm Chipsets Memory Corruption Vulnerability Exploited in Attacks

CISA has warned that a memory corruption flaw in Qualcomm chipsets is being exploited in attacks, urging organizations to promptly apply vendor-provided mitigations.

The issue, tracked as CVE-2026-21385, impacts multiple Qualcomm chipsets and was added to CISA’s catalog on 2026-03-03 with a remediation deadline of 2026-03-24.

While public details remain limited, CISA’s inclusion typically signals credible evidence of real-world exploitation.

CVE-2026-21385 is a memory corruption vulnerability that occurs during memory allocation using alignments across multiple Qualcomm chipsets.

The related weakness is CWE-190 (Integer Overflow or Wraparound), which can cause calculations to “wrap” unexpectedly and lead to incorrect buffer sizes or offsets.

VendorProductCVESummaryCWE
QualcommMultiple ChipsetsCVE-2026-21385Memory corruption while using alignments for memory allocationCWE-190

In practical terms, a flawed size or alignment computation can result in out-of-bounds writes, memory corruption, and crashes.

Potentially code execution in a vulnerable component, depending on where the bug exists and what privileges that component has.

Because Qualcomm chipsets power a wide range of Android phones, tablets, and embedded/IoT devices, overall exposure varies by device.

The risk depends on the vendor, the specific chipset in use, and whether the vulnerable driver, firmware, or software component is present.

At the time of writing, CISA’s note does not state whether the exploitation is tied to ransomware campaigns; that field remains unknown.

Organizations should prioritize patching paths that deliver Qualcomm fixes: OEM firmware updates, device OS/security updates, and any vendor-specific advisories for affected models.

If mitigations are unavailable, CISA advises discontinuing use of the product, and organizations should apply applicable BOD 22-01 guidance for cloud services where relevant to their environment.

For monitoring, focus on signals that can accompany memory corruption exploitation:

Monitoring Focus AreaIndicators to Watch For
Device StabilityUnexpected reboots or instability
Service HealthRepeated crashes in low-level services
Privilege BehaviorAbnormal privilege-related activity after firmware/OS updates

Where feasible, tighten mobile/endpoint controls (MDM compliance, update enforcement, and sideloading restrictions) to reduce the window between disclosure and patch adoption.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Critical Apache Struts Vulnerabilities Enables Remote Code Execution Attacks

Four security flaws described in the supplied Apache Struts advisories could expose affected applications to…

22 minutes ago

Former Infrastructure Engineer Sentenced for Sabotaging Employer’s Windows Network

A former infrastructure engineer has been sentenced to 32 months in federal prison for sabotaging…

33 minutes ago

GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection

A new GitHub Copilot CLI finding that could allow an attacker-controlled web page to guide…

35 minutes ago

From Telemetry to Defense: How SOC and MSSP Leaders Can Build Intelligence-Led Threat Monitoring

Every function in a security operations center, from alert triage to incident response, depends on…

39 minutes ago

ASOS Hacked – App Users Receive Notifications Sent by Hackers

ASOS is investigating a cyber incident after customers received an unauthorized app notification claiming hackers…

1 hour ago

Aembit Extends Access Controls to Personal AI Agents

Silver Springs, United States / Maryland, October 6th, 2026, CyberNewswire Aembit, the identity control plane…

1 hour ago