⚡️ 0-Day Alert: Android Qualcomm msm kernel - exploit in-the-wild since December 2025.
CVE-2026-21385: kgsl msm kernel exploited in the wild
CVE-2026-21385: kgsl uses unsanitized alignment parameter from ioctl and other input vectors to calculate GPU memory allocation variables, leading to memory corruption via an integer overflow.
The bug primitive is powerful enough to allow Elevation of Privilege – not just OOBR.
kgsl is an open source GPU driver in Qualcomm msm kernel that ships in many Android devices.
Patched in 2026-03-05 Android security update.