CVE-2026-0121

LOW

VPU - Use After Free

Title source: llm
STIX 2.1

Description

In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Scores

CVSS v3 2.9
EPSS 0.0001
EPSS Percentile 0.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416 CWE-362
Status published
Products (2)
google/android
Google/Android Android kernel
Published Mar 10, 2026
Tracked Since Mar 11, 2026