IRONSMITHINTEL
HIGHCVSS7.8
|
Actively Exploited
|CISA KEV|CVE-2026-21385|Auth: low — authenticated user|Reboot: required|Manual only

Qualcomm Multiple Chipsets Memory Corruption Vulnerability

Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation.

Published Mar 2, 2026 · Updated May 16, 2026
Why patchRisk explained in plain English
Worst-case scenarioIf unpatched

A local attacker, with a low-privilege account, can achieve full data confidentiality loss, arbitrary modification of data, complete denial of service or system unavailability. Federal agencies are required to remediate by 2026-03-24 under CISA BOD 22-01.

How the attack worksNo clicks needed

This is a Integer Overflow (CWE-190) vulnerability in Qualcomm Multiple Chipsets. Memory corruption while using alignments for memory allocation. Exploitation requires local access, low attack complexity, a low-privilege authenticated account, and no user interaction required.

Am I affected?Quick check

Probably yes if any of these apply:

IT Security
Running sm7675p firmware: -; sm8475p firmware: -; sm8550p firmware: -; sm8635 firmware: -; sm8635p firmware: -; sm8650q firmware: -; sm8750p firmware: -; smart audio 400 platform firmware: -; smart display 200 platform firmware: -; snapdragon 4 gen 1 mobile platform firmware: -; snapdragon 4 gen 2 mobile platform firmware: -; snapdragon 429 mobile platform firmware: -; snapdragon 460 mobile platform firmware: -; snapdragon 480\+ 5g mobile platform firmware: -; snapdragon 480 5g mobile platform firmware: -; snapdragon 6 gen 1 mobile platform firmware: -; snapdragon 6 gen 3 mobile platform firmware: -; snapdragon 6 gen 4 mobile platform firmware: -; snapdragon 625 mobile platform firmware: -; snapdragon 626 mobile platform firmware: -; snapdragon 660 mobile platform firmware: -; snapdragon 662 mobile platform firmware: -; snapdragon 680 4g mobile platform firmware: -; snapdragon 685 4g mobile platform firmware: -; snapdragon 690 5g mobile platform firmware: -; snapdragon 695 5g mobile platform firmware: -; snapdragon 7\+ gen 2 mobile platform firmware: -; snapdragon 7 gen 1 mobile platform firmware: -; snapdragon 778g\+ 5g mobile platform firmware: -; snapdragon 778g 5g mobile platform firmware: -; snapdragon 782g mobile platform firmware: -; snapdragon 7c\+ gen 3 compute firmware: -; snapdragon 7s gen 3 mobile platform firmware: -; snapdragon 8\+ gen 1 mobile platform firmware: -; snapdragon 8\+ gen 2 mobile platform firmware: -; snapdragon 8 elite firmware: -; snapdragon 8 elite gen 5 firmware: -; snapdragon 8 gen 1 mobile platform firmware: -; snapdragon 8 gen 2 mobile platform firmware: -; snapdragon 8 gen 3 mobile platform firmware: -; 5g fixed wireless access platform firmware: -; apq8098 firmware: -; ar8031 firmware: -; ar8035 firmware: -; c-v2x 9150 firmware: -; csra6620 firmware: -; csra6640 firmware: -; fastconnect 6200 firmware: -; fastconnect 6700 firmware: -; fastconnect 6800 firmware: -; fastconnect 6900 firmware: -; fastconnect 7800 firmware: -; flight rb5 5g platform firmware: -; fsm100 platform firmware: -; g1 gen 1 firmware: -; g2 gen 1 firmware: -; iq-615 firmware: -; iq-8275 firmware: -; iq-8300 firmware: -; iq-9075 firmware: -; iq-9100 firmware: -; lemans au lgit firmware: -; lemansau firmware: -; mdm9250 firmware: -; mdm9628 firmware: -; milos firmware: -; monaco iot firmware: -; netrani firmware: -; orne firmware: -; palawan25 firmware: -; pandeiro firmware: -; qam8255p firmware: -; qam8295p firmware: -; qamsrv1h firmware: -; qamsrv1m firmware: -; qca2066 firmware: -; qca6174a firmware: -; qca6391 firmware: -; qca6564a firmware: -; qca6564au firmware: -; qca6574 firmware: -; qca6574a firmware: -; qca6574au firmware: -; qca6584au firmware: -; qca6595 firmware: -; snapdragon 820 automotive platform firmware: -; snapdragon 820am firmware: -; snapdragon 865\+ 5g mobile platform firmware: -; snapdragon 865 5g mobile platform firmware: -; snapdragon 870 5g mobile platform firmware: -; snapdragon 888\+ 5g mobile platform firmware: -; snapdragon 888 5g mobile platform firmware: -; snapdragon ar1\+ gen 1 platform firmware: -; snapdragon ar1 gen 1 platform firmware: -; snapdragon auto 5g modem-rf firmware: -; snapdragon w5\+ gen 1 wearable platform firmware: -; snapdragon x12 lte modem firmware: -; snapdragon x5 lte modem firmware: -; snapdragon x53 5g modem-rf system firmware: -; snapdragon x55 5g modem-rf system firmware: -; snapdragon x65 5g modem-rf system firmware: -; snapdragon xr2\+ gen 1 platform firmware: -; snapdragon xr2 5g platform firmware: -; srv1h firmware: -; srv1m firmware: -; sw5100 firmware: -; sw5100p firmware: -; sw6100 firmware: -; sw6100p firmware: -; sxr2230p firmware: -; sxr2250p firmware: -; sxr2330p firmware: -; sxr2350p firmware: -; themisto firmware: -; video collaboration vc1 platform firmware: -; video collaboration vc3 platform firmware: -; video collaboration vc5 platform firmware: -; vision intelligence 100 platform firmware: -; vision intelligence 200 platform firmware: -; vision intelligence 400 platform firmware: -; wcd9326 firmware: -; wcd9330 firmware: -; wcd9335 firmware: -; wcd9341 firmware: -; wcd9360 firmware: -; qca6595au firmware: -; qca6678aq firmware: -; qca6688aq firmware: -; qca6696 firmware: -; qca6698aq firmware: -; qca6698au firmware: -; qca6797aq firmware: -; qca8081 firmware: -; qca8337 firmware: -; qca8695au firmware: -; qca9367 firmware: -; qca9377 firmware: -; qcm2290 firmware: -; qcm4325 firmware: -; qcm4490 firmware: -; qcm5430 firmware: -; qcm6125 firmware: -; qcm6490 firmware: -; qcn6024 firmware: -; qcn9011 firmware: -; qcn9012 firmware: -; qcn9024 firmware: -; qcs2290 firmware: -; qcs4290 firmware: -; qcs4490 firmware: -; qcs8550 firmware: -; qln1083bd firmware: -; qln1086bd firmware: -; qmp1000 firmware: -; qpa1083bd firmware: -; qpa1086bd firmware: -; qrb5165m firmware: -; qrb5165n firmware: -; qualcomm 215 mobile platform firmware: -; qxm1083 firmware: -; qxm1086 firmware: -; qxm1093 firmware: -; qxm1094 firmware: -; qxm1095 firmware: -; qxm1096 firmware: -; wcd9370 firmware: -; wcd9371 firmware: -; wcd9375 firmware: -; wcd9378 firmware: -; wcd9380 firmware: -; wcd9385 firmware: -; wcd9390 firmware: -; wcd9395 firmware: -; wcn3615 firmware: -; wcn3620 firmware: -; wcn3660b firmware: -; wcn3680b firmware: -; wcn3910 firmware: -; wcn3950 firmware: -; wcn3980 firmware: -; wcn3988 firmware: -; wcn3990 firmware: -; wcn6450 firmware: -; wcn6650 firmware: -; wcn6755 firmware: -; wcn7860 firmware: -; wcn7861 firmware: -; wcn7880 firmware: -; wcn7881 firmware: -; wsa8810 firmware: -; wsa8815 firmware: -; wsa8830 firmware: -; wsa8832 firmware: -; wsa8835 firmware: -; wsa8840 firmware: -; wsa8845 firmware: -; wsa8845h firmware: -; robotics rb2 platform firmware: -; robotics rb5 platform firmware: -; sa4150p firmware: -; sa4155p firmware: -; sa6145p firmware: -; sa6150p firmware: -; sa6155 firmware: -; sa6155p firmware: -; sa7255p firmware: -; sa7775p firmware: -; sa8145p firmware: -; sa8150p firmware: -; sa8155 firmware: -; sa8155p firmware: -; sa8195p firmware: -; sa8255p firmware: -; sa8295p firmware: -; sa8620p firmware: -; sa8770p firmware: -; sa9000p firmware: -; sar1165p firmware: -; sar1250p firmware: -; sar2130p firmware: -; sar2230p firmware: -; sc8380xp firmware: -; snapdragon 8 gen 1 firmware: -; sd626 firmware: -; sd662 firmware: -; sd865 5g firmware: -; sda660 firmware: -; sdm429w firmware: -; sdx61 firmware: -; sm6225p firmware: -; sm6650p firmware: -; sm7325p firmware: -; sm7435 firmware: -; sm7550 firmware: -; sm7550p firmware: -; sm7635p firmware: -; sm7675 firmware: -
Real-world incidentsWhat we've seen

CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2026-03-03 based on evidence of active exploitation in the wild. Federal agencies required to remediate by 2026-03-24.

How to patch

Manual remediation steps

Apply the Vendor Patch

This vulnerability is in the CISA Known Exploited Vulnerabilities catalog — apply the vendor's security update as soon as possible.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

References

    1
    Vendor advisory: https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2026-bulletin.html
    1
    NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2026-21385
    1
    CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21385
PowerShell automationComing soon

No tested PowerShell script for this entry yet. We’re prioritising automation based on user demand.