CVE-2026-0163
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Affected products
- Android
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.3% (25th percentile)
- Weakness
- CWE-416
- NVD status
- Received
- Published
- 2026-08-04
CVE-2026-0163 at NVD
1 known exploit for CVE-2026-0163
Proof-of-concept code and exploit modules indexed by Sploitus