Schwachstelle CVE-2026-21385 in Qualcomm-Komponente für Android ausgenutzt
Autor: info@thehackernews.com (The Hacker News)
⚠️ CVE-Referenzen:
CVE-2026-21385
Zusammenfassung
Google hat eine kritische Sicherheitslücke in einer Qualcomm-Komponente für Android-Geräte bestätigt. Die Schwachstelle CVE-2026-21385 ermöglicht Pufferüberlauf-Angriffe und hat einen CVSS-Score von 7,8. Qualcomm hat einen Patch veröffentlicht, der von Android-Herstellern zeitnah eingespielt werden sollte, um Geräte vor Angriffen zu schützen.
Google on Monday disclosed that a high-severity security flaw impacting an open-source Qualcomm component used in Android devices has been exploited in the wild.
The vulnerability in question is CVE-2026-21385 (CVSS score: 7.8), a buffer over-read in the Graphics component.
"Memory corruption when adding user-supplied data without checking available buffer space," Qualcomm said in an advisory,
Quelle: thehackernews.com