


Perceptive Security
SOC/SIEM Consultancy

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no addi…
Published:
3 August 2026 at 22:00:00
Alert date:
4 August 2026 at 21:03:55
Source:
nvd.nist.gov
Mobile & IoT, Zero-Day Vulnerabilities, Operating Systems
CVE-2026-0163 is a critical use-after-free vulnerability found in multiple functions of vpu_ioctl.c in the Android kernel. The flaw can lead to remote escalation of privilege without requiring any additional execution privileges. No user interaction is needed for exploitation, making it particularly dangerous. The vulnerability was disclosed via the NVD and is referenced in the Google Pixel security bulletin for August 2026. Given the zero-interaction remote exploitation potential, this vulnerability poses a significant risk to affected Android and Pixel devices. It is classified as high severity due to its impact on privilege escalation and remote exploitability.
Technical details
Mitigation steps:
Affected products:
Android
Google Pixel
vpu_ioctl.c
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-0163
https://source.android.com/docs/security/bulletin/pixel/2026/2026-08-01
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
