Description
Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP)
Published: 2026-08-24
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Monitor
AI Analysis

Impact

The vulnerability stems from a use‑after‑free bug in the Zircon kernel pager proxy used by Android. When triggered, an attacker could overwrite freed memory to execute code with kernel privileges, leading to a privilege escalation from userspace to kernel space. The weakness corresponds to CWE‑416, a common memory corruption flaw that can be leveraged for elevated privileges.

Affected Systems

The flaw affects devices running Google Android. No specific version details or product variants are listed in the advisory, so any device using the affected Zircon kernel component may be vulnerable until updated.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the description does not specify remote or local attack requirements, the attack vector is inferred to be local, requiring the attacker to run malicious code from a compromised app or process. Although an exploitation technique is not detailed, the combination of a use‑after‑free in the kernel and the ability to gain kernel privileges makes the risk severe; the CVSS score of 8.8 indicates a high potential impact.

Generated by OpenCVE AI on August 24, 2026 at 20:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android OS security patch that includes the kernel fix, ensuring the device runs a release known to address the issue.
  • If an immediate OS update is unavailable, restrict installation of applications from untrusted or unknown sources and enforce device‑administration policies that limit the permissions granted to apps, thereby reducing the attack surface for privilege escalation.
  • Stay informed by monitoring official security advisories and reputable vulnerability feeds; install official fixes as soon as they become available.

Generated by OpenCVE AI on August 24, 2026 at 20:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Zircon Kernel Use‑After‑Free Leads to Privilege Escalation

Mon, 24 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Mon, 24 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-08-24T17:22:36.043Z

Reserved: 2025-04-16T00:33:54.107Z

Link: CVE-2025-36940

cve-icon Vulnrichment

Updated: 2026-08-24T17:20:42.185Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-24T17:17:21.303

Modified: 2026-08-31T18:50:00.053

Link: CVE-2025-36940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:45:04Z

Weaknesses