CVE-2026-0163Critical· 9.8▾ AbyssalPoC availableIn multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
1 GitHub repo (last check)
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
androidRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-58751Medium· 6.7In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code
CVE-2026-58724High· 7.0In multiple locations, there is a possible use-after-free due to a race condition
CVE-2026-56914High· 8.4In multiple locations, there is a possible use-after-free due to improper locking
CVE-2026-56988Medium· 6.4In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition
CVE-2026-58704High· 8.8In Cellular Modem, there is a possible permission bypass due to a logic error in the code
CVE-2026-0013High· 8.4In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy