Impact
Android vpu_ioctl.c contains a use‑after‑free that may be exploited to elevate privileges from the local user to the system level without requiring any additional execution privileges. This flaw is a classic example of CWE‑416 and would allow a malicious actor to gain root or kernel privileges once the vulnerable ioctl routine is triggered, potentially compromising device integrity and confidentiality.
Affected Systems
The vulnerability affects Google Android devices, notably the Pixel family as referenced in Google’s Security Bulletin for 2026‑08‑01. No specific OS or kernel version is listed in the advisory, so any device running the impacted Android release is potentially affected.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score is not available, but the lack of user interaction required suggests that exploitation could occur automatically, for example via a malicious driver or compromised kernel module. The vulnerability is not listed in CISA KEV, but given its severity, it remains a high‑risk target for attackers that can reach the affected kernel surface.
OpenCVE Enrichment