{"id":"CVE-2026-0163","published":"2026-08-04T19:16:39.213","lastModified":"2026-08-05T05:16:45.103","description":"In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-416"],"vendors":[],"products":[],"references":[{"url":"https://source.android.com/docs/security/bulletin/pixel/2026/2026-08-01","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw involves a use after free vulnerability in vpu_ioctl.c, allowing remote escalation of privilege without additional execution privileges. This is critical as it can be exploited by attackers to gain full control over the system.","exploitability":"Exploitation is relatively straightforward with no user interaction required. The attacker must have network access to the affected system.","blast_radius":"If exploited, the impact is severe as it allows remote attackers to gain full control over the system, potentially leading to data theft, system compromise, and further attacks.","remediation":"Upgrade to the fixed version 2.590 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","privilege-escalation","network"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:02:05.904Z"}}