Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4342 articles · 196587 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-0163
google · android

CVE-2026-0163: In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem

Description

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Products

VendorProductVersions
googleandroidAndroid kernel

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
googleandroidcert_advisory90%

References

  • https://source.android.com/docs/security/bulletin/pixel/2026/2026-08-01

Related News (3 articles)

Tier B
BSI Advisories19d ago
[NEU] [mittel] Google Android Pixel: Schwachstelle ermöglicht Privilegieneskalation
→ No new info (linked only)
Tier B
CERT-FR19d ago
Multiples vulnérabilités dans Google Pixel (05 août 2026)
→ No new info (linked only)
Tier C
VulDB20d ago
CVE-2026-0163 | Google Android VPU vpu_ioctl.c use after free
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
PublishedAug 4, 2026
Trending Score8
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-76035
CVE-2026-76035: Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to ex
Trending: 32
HIGHCVE-2025-36940
CVE-2025-36940: Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from U
Trending: 32
HIGHCVE-2026-76020
CVE-2026-76020: Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside
Trending: 31
HIGHCVE-2026-76017
CVE-2026-76017: Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary cod
Trending: 31
HIGHCVE-2026-76018
CVE-2026-76018: Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engin
Trending: 31

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 4, 2026
Discovered by ZDM
Aug 4, 2026