CVE-2026-0121

LOW

Android - Use-After-Free in VPU

Title source: llm
STIX 2.1

Description

In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Scores

CVSS v3 2.9
EPSS 0.0006
EPSS Percentile 0.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416 CWE-362
Status published
Products (2)
google/android
Google/Android Android kernel
Published Mar 10, 2026
Tracked Since Mar 11, 2026