top of page
perceptive_background_267k.jpg

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no addi…

Published:

4 augustus 2026 om 00:00:00

Alert date:

4 augustus 2026 om 23:03:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Zero-Day Vulnerabilities, Operating Systems

CVE-2026-0163 is a critical use-after-free vulnerability found in multiple functions of vpu_ioctl.c in the Android kernel. The flaw can lead to remote escalation of privilege without requiring any additional execution privileges. No user interaction is needed for exploitation, making it particularly dangerous. The vulnerability was disclosed via the NVD and is referenced in the Google Pixel security bulletin for August 2026. Given the zero-interaction remote exploitation potential, this vulnerability poses a significant risk to affected Android and Pixel devices. It is classified as high severity due to its impact on privilege escalation and remote exploitability.

Technical details

Mitigation steps:

Affected products:

Android
Google Pixel
vpu_ioctl.c

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page