Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4365 articles · 196628 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2025-36940PATCHED
google · android

CVE-2025-36940: Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from U

Description

Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP)

Affected Products

VendorProductVersions
googleandroidF30.1.1

References

  • https://support.google.com/product-documentation/answer/17072818?hl=en&ref_topic=12974021&sjid=10451061435205708316-NC(vendor-advisory)

Related News (1 articles)

Tier C
VulDB3h ago
CVE-2025-36940 | Google Fuchsia F30.1.1 Pager Proxy use after free
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://support.google.com/product-documentation/answer/17072818?hl=en&ref_topic=12974021&sjid=10451061435205708316-NC
PublishedAug 24, 2026
Trending Score32
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-76035
CVE-2026-76035: Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to ex
Trending: 32
HIGHCVE-2026-76020
CVE-2026-76020: Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside
Trending: 31
HIGHCVE-2026-76017
CVE-2026-76017: Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary cod
Trending: 31
HIGHCVE-2026-76018
CVE-2026-76018: Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engin
Trending: 31
HIGHCVE-2026-76023
CVE-2026-76023: Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker wh
Trending: 31

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 24, 2026
Discovered by ZDM
Aug 24, 2026
Patch Available
Aug 24, 2026