• PoC PUBLIC

CVE-2026-0163: use-after-free privilege escalation in Google Android

An attacker can remotely trigger a use-after-free in the Android kernel to escalate privileges on affected devices, tracked as CVE-2026-0163. The flaw is in the Android kernel's vpu_ioctl handling and permits privilege escalation without any user interaction or prior authentication; the CVSS vector indicates network attackability with no privileges or UI required. Vendor guidance lists the Android kernel as affected; no fixed kernel versions are provided in the advisory data.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00382
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code exists while no patch is available, so prioritize reducing exposure of Android devices, applying any vendor mitigations, and increasing detection for kernel compromise.

What is CVE-2026-0163?

An attacker can remotely trigger a use-after-free in the Android kernel to escalate privileges on affected devices, tracked as CVE-2026-0163. The flaw is in the Android kernel's vpu_ioctl handling and permits privilege escalation without any user interaction or prior authentication; the CVSS vector indicates network attackability with no privileges or UI required. Vendor guidance lists the Android kernel as affected; no fixed kernel versions are provided in the advisory data. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Google Android are affected?

BRANCHAFFECTEDFIXED
AndroidAndroid kernel

Is CVE-2026-0163 being exploited?

Public exploit code is available.

How to fix CVE-2026-0163

  1. Restrict network exposure of affected Android devices and services that interact with the kernel's vpu_ioctl interface.
  2. Apply any vendor-provided mitigations or configuration guidance immediately.
  3. Increase host and network monitoring for indicators of kernel-level compromise and unusual privilege escalations.
  4. Plan rapid deployment of a kernel update as soon as Google or device vendors publish a fixed version.

Frequently asked questions

Is CVE-2026-0163 being actively exploited?

Public exploit code for CVE-2026-0163 is available, but there are no public reports of widespread active exploitation as of 2026-09-29.

Which Android versions are affected by CVE-2026-0163?

The advisory identifies the Android kernel as affected; specific Android release numbers or device models are not specified in the provided facts.

Is there a patch for CVE-2026-0163?

No patch is listed in the provided data; no fixed kernel versions are identified.

Does CVE-2026-0163 require authentication?

No. Exploitation does not require prior authentication or user interaction according to the vulnerability data.

References