VORANT. Threat Intelligence Sign in Get the full feed

Google patched 100+ Android vulnerabilities including CVE-2026-21385 under active…

critical vulnerability

Google patched 100+ Android vulnerabilities including CVE-2026-21385 under active exploit, enabling remote code execution and privilege escalation across Framework, System, and chipset components.

Google released the March 2026 Android security bulletin addressing over 100 vulnerabilities affecting Android OS patch levels prior to 2026-3-5. The most severe flaws enable remote code execution in the System component and privilege escalation across Framework, System, and Kernel layers. Successful exploitation allows attackers to install programs, modify or delete data, and create privileged accounts.

Critically, Google confirmed that CVE-2026-21385, a vulnerability in Qualcomm components, is under limited, targeted exploitation in the wild. The bulletin also addresses numerous elevation-of-privilege vulnerabilities in Framework (26 CVEs), System (7 CVEs), and Kernel (15 CVEs), plus flaws in third-party chipset components from Qualcomm, Arm, MediaTek, Imagination Technologies, and Unisoc.

The advisory classifies exploitation under MITRE ATT&CK technique T1203 (Exploitation for Client Execution). Organizations are urged to apply the March 2026 security patch immediately, particularly given the active exploitation of at least one Qualcomm component vulnerability.

Mentioned in this report

Vulnerabilities CVE-2024-43859CVE-2025-32313CVE-2025-38616CVE-2025-38618CVE-2025-48544CVE-2025-48567CVE-2025-48568CVE-2025-48574CVE-2025-48577CVE-2025-48578CVE-2025-48579CVE-2025-48582CVE-2025-48602CVE-2025-48605CVE-2025-48619CVE-2025-48634CVE-2025-48635CVE-2025-48641CVE-2025-48645CVE-2025-48646CVE-2025-48650CVE-2025-48653CVE-2025-48654CVE-2026-0006CVE-2026-0007CVE-2026-0008CVE-2026-0010CVE-2026-0011CVE-2026-0013CVE-2026-0017CVE-2026-0020CVE-2026-0021CVE-2026-0023CVE-2026-0026CVE-2026-0034CVE-2026-0035CVE-2026-0037CVE-2026-0038CVE-2026-0047CVE-2026-21385KEV

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-android-os-could-allow-for-remote-code-execution_2026-017

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free