{"id":"CVE-2026-0163","published":"2026-08-04T19:16:39.213","lastModified":"2026-08-05T05:16:45.103","description":"In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-416"],"vendors":[],"products":[],"references":[{"url":"https://source.android.com/docs/security/bulletin/pixel/2026/2026-08-01","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw involves a use after free vulnerability in vpu_ioctl.c, allowing remote escalation of privilege without user interaction.","exploitability":"Exploitation is relatively straightforward with no additional execution privileges required beyond initial access.","blast_radius":"If exploited, the impact could be severe as it allows for remote privilege escalation affecting potentially all system resources.","remediation":"Update to the latest vendor patch or version that addresses this vulnerability.","tags":["rce","privilege-escalation","remote-exploit","vulnerability"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:42:09.751Z"}}