T

Threats

Google Patches Android Kernel Privilege Escalation Vulnerability

Google has released a Pixel security update for CVE-2026-0163, a use-after-free vulnerability in multiple functions of vpu_ioctl.c within the Video Processing Unit component.

CISA's ADP enrichment assigns a CVSS 3.1 score of 9.8, Critical. Google's Pixel Update Bulletin rates the vulnerability High. The flaw could allow remote privilege escalation with no additional execution privileges and no user interaction.

CISA's SSVC assessment recorded no known exploitation as of 4 August 2026. Organisations should not delay patching because the vulnerability is network-accessible, requires no privileges and may have a total technical impact.


Overview

  • CVE: CVE-2026-0163

  • Vendor: Google

  • Product: Android on supported Pixel devices

  • Component: Android kernel, Video Processing Unit

  • Vulnerability type: Use after free, CWE-416

  • Overall severity: Critical, CVSS 3.1 score 9.8 from CISA ADP

  • Vendor severity: High

  • Publication date: 4 August 2026

  • Updated: 4 August 2026

  • Known exploitation: None reported in CISA's SSVC assessment at publication


Affected Versions

Google Android Kernel on Supported Pixel Devices

  • Affected: Android kernel implementations on supported Pixel devices containing the vulnerable Video Processing Unit code. The vendor has not specified an exact affected-version range as of 4 August 2026.

  • Fixed: Google devices with a security patch level of 2026-08-05 or later address this issue.

  • Not affected: The CVE record marks configurations outside the listed Android kernel scope as unaffected by default. Google has not published a more specific unaffected model, Android version or configuration list.

  • Source: Google Pixel Update Bulletin - August 2026


Vulnerability Breakdown

CVE-2026-0163 - Android Kernel Use After Free

  • Severity: Critical by CVSS score, vendor-rated High

  • CVSS: 9.8, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • Description: Multiple functions in vpu_ioctl.c contain a use-after-free condition. The issue affects the Video Processing Unit within the Android kernel on supported Pixel devices.

  • Impact: Successful exploitation could allow remote escalation of privilege and compromise the confidentiality, integrity and availability of the affected device.

  • Conditions: Network access is sufficient according to the CVSS vector. No prior privileges or user interaction are required.

  • Notes: CISA's SSVC assessment listed exploitation as none, automatable as yes and technical impact as total on 4 August 2026.


Mitigation

  • Apply the Google Pixel update that provides the 2026-08-05 security patch level or later.

  • Verify the Android security patch level on all supported Pixel devices after deployment.

  • Use mobile device management controls to identify devices below the required patch level and restrict their access to sensitive organisational resources until updated.

  • Prioritise internet-connected, privileged and business-critical devices.

  • Monitor Google's Pixel Update Bulletin for revisions or additional guidance.


Summary for IT Teams

  • Products: Google Android on supported Pixel devices

  • Threat Level: Critical, CVSS 9.8 from CISA ADP. Google rates the issue High.

  • Action Required: Update affected Pixel devices to the 2026-08-05 security patch level or later, verify deployment and restrict devices that remain unpatched.


Reference


Need Help?

If your organisation needs assistance assessing or patching Android devices, contact Secure ISS on 1300 769 460. The Secure ISS SOC team is ready to help strengthen your cybersecurity posture.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.