CVE-2026-0125
published 2026-06-16CVE-2026-0125: In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no…
PriorityP425high7.1
EPSS
0.07%
0.0th percentile
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android vpu_ioctl.c use after free
vuldb·2026-06-16
CVE-2026-0125 [CRITICAL] Google Android vpu_ioctl.c use after free
A vulnerability was found in Google Android. It has been declared as critical. Impacted is an unknown function of the file vpu_ioctl.c. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2026-0125. The attack requires local access. There is no available exploit.
GHSA
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition.
ghsa_unreviewed·2026-06-16
CVE-2026-0125 [HIGH] CWE-416 In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition.
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published