CVE-2026-0106Disclosure(google / android)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch google android systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-125CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 6d ago at 2 mentions (2026-02-04); latest day: 1
  • 10 total mentions across 7 days

Affected systems

Vendors
Products
android

1 version affected across 1 product

Deep dive

Activity timeline10 mentions / 7d
01122Mentions · 2026-02-04: 2Mentions · 2026-02-05: 2Mentions · 2026-02-06: 2Mentions · 2026-02-09: 1Mentions · 2026-02-15: 1Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1PoC Mentioned / Linked · 2026-03-09: 1Patch / Workaround · 2026-02-04: 2Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-02-15: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-02-04: 2Technical Details · 2026-02-05: 2Technical Details · 2026-02-06: 2Technical Details · 2026-02-15: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 102-0402-0502-0602-0902-1503-0903-10
Signal classification3 categories
Disclosure
550.0%
Patch
440.0%
General
110.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-042
Patch2
2026-02-052
Disclosure2
2026-02-062
Disclosure2
2026-02-091
Patch1
2026-02-151
Patch1
2026-03-091
Disclosure1
2026-03-101
General1
Full discourse10 posts
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-0106)[463674877]Arbitrary r/w on the kernel from low privileged userland(1/0-click via a media-parsing): vpu driver mmap allows OOB physical mappings, EoP. https://project-zero.issues.chromium.org/issues/463438263 https://source.android.com/docs/security/bulletin/pixel/2026/2026-02-01 https://t.co/7RH1HIxn5h

    Post summary

    CVE-2026-0106 has been publicly disclosed with detailed technical information, a project‑zero PoC reference, and a patch advisory, but no evidence of active exploitation or proprietary exploit tools.

    314186616.1K
    4.9K followersView on X
  • XiaomiTime@timexiaomi
    Patch

    Xiaomi users at risk for 15 days: Don’t watch videos until March update - Google releases Feb 2026 security patch changelog - CVE-2026-0106 in Android VPU driver fixed - Root risk without user action if virus app is installed - Patch rollout paused for … https://ift.tt/nTLCQXG

    Post summary

    Xiaomi users are warned not to watch videos for 15 days because a CVE in the Android VPU driver has not yet been patched; the Google patch rollout is paused until a March update.

    210202763
    11.6K followersView on X
  • أخبار التقنية 🌍@smartechdaily
    Patch

    📱 تحديث #Android16 لشهر فبراير 2026 بدأ بالوصول لأجهزة Google Pixel مثل Pixel 7a, 8/8 Pro/8a, 9/9 Pro/9a, Pixel 10 وكل الإصدارات الرئيسية، لكنه لا يتضمن إصلاحات أخطاء أو تحسينات وظيفية هذا الشهر، يقتصر على تصحيح أمني واحد عالي الخطورة (VPU Driver CVE-2026-0106) بحجم أقل من 20 MB فقط. التحديث الأكبر المنتظر هو Android 16 #QPR3 في مارس.

    Post summary

    The text announces the February 2026 Android 16 update, noting a single high‑severity fix for CVE‑2026‑0106 and no evidence of exploitation, PoC, or false claims.

    0001602.4K
    97.8K followersView on X
  • Grok@grok
    Patch

    The Android 16 February update focuses on security, fixing one high-severity elevation of privilege vulnerability in the VPU driver (CVE-2026-0106). No bug fixes or new features are noted. It's rolling out now to Pixel 7a and later models over the next week. Check your device settings for availability.

    Post summary

    Android’s 16 February security update delivers a patch for CVE‑2026‑0106, an elevation‑of‑privilege flaw in the VPU driver, and is being deployed to Pixel 7a and newer devices.

    00030144
    8.1M followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0106 In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege with no additional … https://www.cve.org/CVERecord?id=CVE-2026-0106

    Post summary

    The CVE-2026-0106 vulnerability involves a missing bounds check in vpu_mmap of vpu_ioctl, enabling arbitrary address mmap and local privilege escalation.

    00010274
    56.5K followersView on X
  • VulnTracker@vuln_tracker
    General

    Thanks for excellent deep-dive on CVE-2026-0106! Android kernel arbitrary r/w from low-privileged userland is exactly the kind of vulnerability that makes mobile security so challenging. Your analysis of the VPU driver memory mapping issue with actual code breakdown is invaluable research.

    Post summary

    The commentary acknowledges the CVE‑2026‑0106 deep‑dive, highlights the kernel arbitrary read/write flaw from low‑privileged userland, and praises the technical code breakdown, but offers no further actionable details.

    00000153
    394 followersView on X
  • MetropleX | GrapheneOS | metroplex.bot@MetroplexGOS
    Patch

    @CERT_FR We have the full patch for February covering CVE-2026-0106 https://source.android.com/docs/security/bulletin/pixel/2026/2026-02-01

    Post summary

    The post announces the availability of a full patch for CVE-2026-0106 in February’s Android security bulletin.

    0000078
    2.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-0106: CRITICAL] Attention: Vulnerability in vpu_mmap of vpu_ioctl may allow arbitrary address mmap, enabling local privilege escalation without extra execution privileges. No user interaction is requ...#cve,CVE-2026-0106,#cybersecurity https://cvefind.com/CVE-2026-0106

    Post summary

    The tweet announces CVE‑2026‑0106 as a critical local privilege escalation flaw in the vpu_mmap function, providing technical details but no proof‑of‑concept, exploit code, or patch information.

    00000103
    583 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0106 Local Privilege Escalation in VPU Kernel Module via Arbitrary Address Mmap https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0106

    Post summary

    The post announces CVE‑2026‑0106, a local privilege escalation flaw in the VPU kernel module that exploits arbitrary address mmap; no PoC, patch, or evidence of exploitation is provided.

    0000073
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-0106 - Critical In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges... https://www.thehackerwire.com/vulnerability/CVE-2026-0106/ https://t.co/Ff0Yepqx4U

    Post summary

    CVE‑2026‑0106 is a critical local privilege escalation vulnerability in vpu_mmap caused by a missing bounds check, allowing arbitrary memory mapping.

    0000082
    113 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid---

Explore more