CVE detail
CVE-2026-0038
In multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- Android devices hit by exploited Qualcomm flaw CVE-2026-21385Security Affairs
Google confirms that the Qualcomm Android vulnerability CVE-2026-21385 was exploited in real-world attacks. Google has confirmed that CVE-2026-21385 (CVSS score of 7.8), a high-severity vulnerability affecting an open-source Qualcomm component used in Android devices, has been actively exploited. “There are indications that CVE-2026-21385 may be under limited, targeted exploitation.” reads Google’s advisory. The flaw is […]
newssecurityaffairs.comMar 3, 2026, 10:03 AM - Android’s March 2026 security patch fixes over 100 flaws, one under targeted exploitationHelp Net Security
The Android March 2026 security patch addresses vulnerabilities across dozens of components and includes one CVE confirmed under active exploitation. Devices running a patch level of 2026-03-05 or later receive fixes for all disclosed issues. Android March 2026 security patch includes one CVE under active exploitation The bulletin notes indications that CVE-2026-21385 may be under limited, targeted exploitation. The flaw resides in the Qualcomm Display component and is rated High severity. Organizations running devices with … More →
newswww.helpnetsecurity.comMar 3, 2026, 9:38 AM - https://source.android.com/docs/security/bulletin/2026/2026-03-01source.android.com
No excerpt available.
Vendor Advisorysource.android.comMar 2, 2026, 7:16 PM - https://android.googlesource.com/kernel/common/+/f090d4b083a9ef4831f99e692c239542dd385cb4android.googlesource.com
No excerpt available.
Patchandroid.googlesource.comMar 2, 2026, 7:16 PM - https://android.googlesource.com/kernel/common/+/d884f499434c224285c30d460681f1ce76a8cf1fandroid.googlesource.com
No excerpt available.
Patchandroid.googlesource.comMar 2, 2026, 7:16 PM - https://android.googlesource.com/kernel/common/+/b23a5bfa1fb8f9525e21f095a87486a2bd856321android.googlesource.com
No excerpt available.
Patchandroid.googlesource.comMar 2, 2026, 7:16 PM - https://android.googlesource.com/kernel/common/+/7e1d15d29b7fe0f858926a8bcaf929b75db9e52aandroid.googlesource.com
No excerpt available.
Patchandroid.googlesource.comMar 2, 2026, 7:16 PM - https://android.googlesource.com/kernel/common/+/652b7b6bf9a62cc12c3a071bab4e92314f046739android.googlesource.com
No excerpt available.
Patchandroid.googlesource.comMar 2, 2026, 7:16 PM - https://android.googlesource.com/kernel/common/+/513ea99ae008b81dd266bf6e361627c058ddde41android.googlesource.com
No excerpt available.
Patchandroid.googlesource.comMar 2, 2026, 7:16 PM - https://android.googlesource.com/kernel/common/+/1bf8033b56a45165602f8116e0a0d2e767f1e8aeandroid.googlesource.com
No excerpt available.
Patchandroid.googlesource.comMar 2, 2026, 7:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16424CVSS 9.6 · Critical
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escap…
- CVE-2026-16419CVSS 9.6 · Critical
Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page…
- CVE-2026-15900CVSS 9.6 · Critical
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium secu…
- CVE-2026-48357CVSS 6.2 · Medium
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerab…
- CVE-2026-48354CVSS 6.2 · Medium
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulner…
- CVE-2026-48353CVSS 5.5 · Medium
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to ac…