# Google patches 100+ Android flaws, CVE-2026-21385 exploited

Published: 2026-03-04 · Severity: high
Canonical: https://vorant.io/reports/d080cbd4-6736-5b34-894d-9a4b326524a7/google-patches-100-android-flaws-cve-2026-21385-exploited

> Google patched over 100 vulnerabilities in Android OS, including CVE-2026-21385, a Qualcomm flaw under limited targeted exploitation that could enable remote code execution.

Google has released its March 2026 Android security bulletin addressing multiple vulnerabilities across the Android operating system, with the most severe flaws enabling remote code execution. The advisory covers patches for vulnerabilities spanning the Android Framework, System components, kernel, and third-party chipset components from Arm, Qualcomm, MediaTek, Imagination Technologies, and Unisoc. Affected devices include those running Android OS patch levels prior to 2026-3-5.

The most critical aspect of this bulletin is CVE-2026-21385, a Qualcomm component vulnerability that Google indicates is under limited, targeted exploitation in the wild. Successful exploitation of the most severe vulnerabilities could allow attackers to execute arbitrary code, potentially leading to full device compromise. Depending on the privileges associated with the exploited component, attackers could install programs, access or modify data, or create new accounts with elevated rights.

The bulletin addresses 26 Framework elevation-of-privilege vulnerabilities, 7 System elevation-of-privilege flaws, 15 kernel privilege escalation issues, and multiple vulnerabilities in vendor-specific components. Lower-severity issues include information disclosure and denial-of-service vulnerabilities. Organizations are advised to apply the March 2026 security patches immediately following appropriate testing, particularly for devices in sensitive environments given the active exploitation of at least one vulnerability.

## Mentioned in this report

- Vulnerabilities: CVE-2024-43859, CVE-2025-32313, CVE-2025-38616, CVE-2025-38618, CVE-2025-48544, CVE-2025-48567, CVE-2025-48568, CVE-2025-48574, CVE-2025-48577, CVE-2025-48578, CVE-2025-48579, CVE-2025-48582, CVE-2025-48602, CVE-2025-48605, CVE-2025-48619, CVE-2025-48634, CVE-2025-48635, CVE-2025-48641, CVE-2025-48645, CVE-2025-48646, CVE-2025-48650, CVE-2025-48653, CVE-2025-48654, CVE-2026-0006, CVE-2026-0007, CVE-2026-0008, CVE-2026-0010, CVE-2026-0011, CVE-2026-0013, CVE-2026-0017, CVE-2026-0020, CVE-2026-0021, CVE-2026-0023, CVE-2026-0026, CVE-2026-0034, CVE-2026-0035, CVE-2026-0037, CVE-2026-0038, CVE-2026-0047, CVE-2026-21385 (KEV)

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-android-os-could-allow-for-remote-code-execution_2026-017

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d080cbd4-6736-5b34-894d-9a4b326524a7/google-patches-100-android-flaws-cve-2026-21385-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
