CVE-2026-96812High· 8.8▾ TwilightImproper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character device node in a container image, opening the device passes through to the host, allowing the sandboxed attacker to register a host device and exploit CUSE unrestricted ioctl handling to overwrite root udev helper memory.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-0179Medium· 6.7In Bootloader, there is a possible permission bypass due to a missing permission check
CVE-2026-28659High· 7.8In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check
CVE-2026-0009High· 7.8In multiple locations, there is a possible tapjacking due to a logic error in the code
CVE-2026-0091High· 7.8In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user
CVE-2026-0089High· 7.8In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check
CVE-2026-0086Medium· 6.8In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check