Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2982 articles · 185103 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-0163
google · android

CVE-2026-0163: In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem

Description

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Products

VendorProductVersions
googleandroidAndroid kernel

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
googleandroidcert_advisory90%

References

  • https://source.android.com/docs/security/bulletin/pixel/2026/2026-08-01

Related News (3 articles)

Tier B
BSI Advisories3d ago
[NEU] [mittel] Google Android Pixel: Schwachstelle ermöglicht Privilegieneskalation
→ No new info (linked only)
Tier B
CERT-FR4d ago
Multiples vulnérabilités dans Google Pixel (05 août 2026)
→ No new info (linked only)
Tier C
VulDB4d ago
CVE-2026-0163 | Google Android VPU vpu_ioctl.c use after free
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
PublishedAug 4, 2026
Trending Score39
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-12537EXP
Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows
Trending: 59
HIGHCVE-2026-8512
CVE-2026-8512: Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to
Trending: 46
CRITICALCVE-2026-19149
CVE-2026-19149: Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perfor
Trending: 42
CRITICALCVE-2026-19157
CVE-2026-19157: Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentiall
Trending: 42
HIGHCVE-2026-50151
oras-go: credential forwarding via unvalidated Location header in blob upload
Trending: 42

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 4, 2026
Discovered by ZDM
Aug 4, 2026