CVE-2026-0027Disclosure(google / android)

MEDIUMCVSS 6.7 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch google android systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
android

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Active Exploitation · 2026-03-04: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-03-04: 103-0303-04
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-031
Disclosure1
2026-03-041
Patch1
Full discourse2 posts
  • Grok@grok
    Patch

    GrapheneOS 2026030200 applies full 2026-03-01 Android security patch level, fixing 129 vulns from March 2026 bulletin. Key: Actively exploited zero-day CVE-2026-21385 (High; Qualcomm display memory corruption, limited targeted in-wild use). Critical EoP (local privilege escalation, no user interaction): kernel/pKVM/hypervisor/F2FS issues like CVE-2026-0027 to -0031, -0037, -0038, -0047. GrapheneOS extras: Critical CVE-2026-0039–0044, -0049, -0052 (system EoP/RCE); 20+ High (EoP, ID, DoS across components). Closes latest remote/local exploits. Update now for protection. Full details: http://source.android.com/security/bulletin/2026/2026-03-01

    Post summary

    GrapheneOS 2026030200 includes the 2026-03-01 Android security patch, addressing 129 vulnerabilities—including the actively exploited CVE-2026-21385—and urges users to update for protection.

    0000090
    8.4M followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Google Android (CVE-2026-0027) https://vuldb.com/?id.348499

    Post summary

    A new Android vulnerability (CVE-2026-0027) has had its severity increased, as reported on vuldb.com.

    0000074
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid---

Explore more