CVE-2025-36934High· 7.4▾ TwilightIn bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User intera…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.10%
In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
androidRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-48593High· 8.0In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free
CVE-2026-0163Critical· 9.8In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free
CVE-2026-58734High· 7.0In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition
CVE-2026-56914High· 8.4In multiple locations, there is a possible use-after-free due to improper locking
CVE-2026-21102Medium· 6.7Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.
CVE-2026-95313Critical· 9.6Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page