Android Update Patches Exploited Qualcomm Zero-Day
2026-03-04T21:52:18Z•50d5001de7ba4f7deba2a91af0225b801ad09c5f0a49024d48d06c81da4955d7
2025 campaignai-securityair-gapped systemsandroidaptchromecredential brute forcedata breachexploit in the wildfull system compromisegemini liveinput sanitizationinteger overflowlocalhostmadison square gardenmalicious extensionsmalware implants','propagation tools','tiresensor tracking','vehmemory corruptionms-agentnorth koreaopenclaworacle ebsqualcommwebsocketzero-day
What happened
SecurityWeek roundup: Google and vendors pushed an Android update to patch an actively exploited Qualcomm zero-day (integer overflow/wraparound in the Qualcomm graphics component leading to memory corruption). Multiple high‑impact agent/AI vulnerabilities were disclosed — improper input sanitization in the MS‑Agent AI framework enabling full system compromise via the Shell tool; a Chrome Gemini Live flaw that allowed malicious extensions to spy and exfiltrate files; and an OpenClaw gateway issue where websites could open localhost WebSocket connections, brute‑force gateway credentials and take
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 50d5001de7ba4f7deba2a91af0225b801ad09c5f0a49024d48d06c81da4955d7
- Enrichment time
- 2026-03-04T21:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.