2.9
CVE-2026-0121 - UseโAfterโFree Race Condition in Android VPU Leading to Local Information Disclosure
In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
9.8
CVE-2026-0120 -
In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
6.8
CVE-2026-0119 - Out of Bounds Write in Android USIM Registration Leading to Physical Privilege Escalation
In usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible out of bounds write due to memory corruption. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
8.4
CVE-2026-0118 - OOBConfig Carrier Restriction Bypass Leading to Local Privilege Escalation
In oobconfig, there is a possible bypass of carrier restrictions due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
8.4
CVE-2026-0117 - Android MFC Decoder OutโofโBounds Write Allowing Local Privilege Escalation
In mfc_dec_dqbuf of mfc_dec_v4l2.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
9.8
CVE-2026-0116 -
In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
2.1
CVE-2026-0115 - Android TEE SideโChannel Key Leak Allowing Physical Information Disclosure
In Trusted Execution Environment, there is a possible key leak due to side channel information disclosure. This could lead to physical information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
9.8
CVE-2026-0114 - OutโofโBounds Write in Android Modem Leading to Remote Code Execution
In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
9.8
CVE-2026-0113 - OutโOfโBounds Write in Android SMS Utility Leading to Remote Privilege Escalation
In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
7.4
CVE-2026-0112 -
In vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.