DIRAS TAKE
Urgent: public exploit code exists while no patch is available, so prioritize reducing exposure of Android devices, applying any vendor mitigations, and increasing detection for kernel compromise.
What is CVE-2026-0163?
An attacker can remotely trigger a use-after-free in the Android kernel to escalate privileges on affected devices, tracked as CVE-2026-0163. The flaw is in the Android kernel's vpu_ioctl handling and permits privilege escalation without any user interaction or prior authentication; the CVSS vector indicates network attackability with no privileges or UI required. Vendor guidance lists the Android kernel as affected; no fixed kernel versions are provided in the advisory data. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Google Android are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Android | Android kernel |
Is CVE-2026-0163 being exploited?
Public exploit code is available.
How to fix CVE-2026-0163
- Restrict network exposure of affected Android devices and services that interact with the kernel's vpu_ioctl interface.
- Apply any vendor-provided mitigations or configuration guidance immediately.
- Increase host and network monitoring for indicators of kernel-level compromise and unusual privilege escalations.
- Plan rapid deployment of a kernel update as soon as Google or device vendors publish a fixed version.
Frequently asked questions
Is CVE-2026-0163 being actively exploited?
Public exploit code for CVE-2026-0163 is available, but there are no public reports of widespread active exploitation as of 2026-09-29.
Which Android versions are affected by CVE-2026-0163?
The advisory identifies the Android kernel as affected; specific Android release numbers or device models are not specified in the provided facts.
Is there a patch for CVE-2026-0163?
No patch is listed in the provided data; no fixed kernel versions are identified.
Does CVE-2026-0163 require authentication?
No. Exploitation does not require prior authentication or user interaction according to the vulnerability data.
References
- nvd.nist.gov/vuln/detail/CVE-2026-0163
- cve.org/CVERecord?id=CVE-2026-0163
- source.android.com/docs/security/bulletin/pixel/2026/2026-08-01
- All Google CVEs on CVE Radar
- CVEs published in September 2026