CVE-2026-56960: pre-auth privilege escalation in Google Android

A remote attacker can escalate privileges on the Android kernel without any user interaction or prior authentication. CVE-2026-56960 is a use-after-free vulnerability in multiple kernel locations that can lead to full compromise of device privileges. The flaw affects the Android kernel (affected branch: Android); no fixed versions are listed. Exploitation requires only network access to a vulnerable device and does not require a user to click or an account on the device.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00401
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: the flaw requires no authentication or user interaction, enabling remote escalation from network access to kernel privileges; prioritize exposure reduction and monitoring until a vendor fix is available.

What is CVE-2026-56960?

A remote attacker can escalate privileges on the Android kernel without any user interaction or prior authentication. CVE-2026-56960 is a use-after-free vulnerability in multiple kernel locations that can lead to full compromise of device privileges. The flaw affects the Android kernel (affected branch: Android); no fixed versions are listed. Exploitation requires only network access to a vulnerable device and does not require a user to click or an account on the device. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Google Android are affected?

BRANCHAFFECTEDFIXED
AndroidAndroid kernel

Is CVE-2026-56960 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-56960

  1. Restrict network exposure of Android devices—block untrusted network access and limit services reachable from the internet.
  2. Apply vendor security guidance and install Android updates immediately once Google publishes a patch for the kernel.
  3. Enable and monitor kernel and device logs for unusual privilege escalation activity and signs of exploitation.
  4. Isolate high-risk devices on segmented networks and enforce least-privilege policies for device users and services.

Frequently asked questions

Is CVE-2026-56960 being actively exploited?

There are no public reports of active exploitation of CVE-2026-56960 as of 2026-09-29.

Which Android versions are affected by CVE-2026-56960?

CVE-2026-56960 affects the Android kernel (affected branch: Android); the facts list the Android kernel as affected but do not specify particular version numbers.

Is there a patch for CVE-2026-56960?

No patch is listed in the provided facts; the affected entry shows no fixed versions, so apply mitigations and install vendor updates when Google releases a fix.

Does CVE-2026-56960 require authentication?

No—CVE-2026-56960 does not require authentication or user interaction and can be exploited with only network access to a vulnerable Android device.

References