Description
In VPU, there is a possible information dislclosure due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a logic error in the Video Processing Unit that reads sensitive data without proper authorization, representing a CWE-200 data exposure weakness. An attacker with system execution privileges can exploit the flaw to locally disclose information. The flaw does not require user interaction, enabling abuse after the attacker has already gained local access.

Affected Systems

Google has identified the vulnerability in its Android operating system. No specific device models or OS versions are listed, so the flaw may affect any device running the affected Android build where the VPU component is present.

Risk and Exploitability

The advisory assigns a CVSS score of 4.4, classifying the issue as Low severity. The EPSS score is 0.00077 (<1%) and vulnerability is not listed in CISA’s KEV catalog. Exploitation requires system-level permissions, so only local attackers with elevated privileges can disclose data. Because no user interaction is needed, an attacker who has already compromised the device can read memory or data associated with the VPU. The local nature of the exploitation limits the potential impact to the device itself, but the information disclosed could be sensitive and compromise privacy or facilitate further attacks.

Generated by OpenCVE AI on September 20, 2026 at 14:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Android security patch from Google as soon as it is available.
  • Configure applications to run with the least privileges required and avoid granting full system execution rights.
  • If a patch is not yet released, enforce runtime permissions that restrict access to VPU memory and monitor for abnormal data reads by observing system logs.

Generated by OpenCVE AI on September 20, 2026 at 14:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title VPU Logic Error Allowing Local Information Disclosure

Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title VPU Logic Error Allowing Local Information Disclosure

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In VPU, there is a possible information dislclosure due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-15T20:32:25.083Z

Reserved: 2025-10-23T08:45:51.643Z

Link: CVE-2026-0197

cve-icon Vulnrichment

Updated: 2026-09-15T20:32:16.791Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:14.940

Modified: 2026-09-21T17:21:18.730

Link: CVE-2026-0197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:15:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor