ZeroHour

CVE-2026-55318

mass

Use-After-Free Race Condition in Google Android Enables Remote Code Execution

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-55318 is a use-after-free vulnerability caused by a race condition in multiple locations of Google's Android platform, assigned by Google's Android security CNA ([email protected]). An attacker who wins the race can cause memory to be accessed after it has been freed, corrupting process memory and achieving remote code execution in the context of the affected component with no additional execution privileges required. The CVSS 3.1 score of 8.8 (AV:N/AC:L/PR:L/UI:N) indicates the flaw is reachable over the network with low attack complexity, requires only low privileges, needs no user interaction, and can fully compromise confidentiality, integrity, and availability. Any Android device shipping the vulnerable component is affected, though the advisory data provided does not enumerate the specific components or version ranges. No public proof of concept is known and the flaw is not in CISA's Known Exploited Vulnerabilities catalog, so no in-the-wild exploitation has been observed.

What to do: Apply the fix as soon as Google publishes the corresponding Android Security Bulletin update, and verify device security patch levels and Google Play system updates afterward. Enterprises with managed Android fleets should prioritize the OTA rollout once the bulletin lands, since exploitation requires no user interaction and yields code execution. Monitor for a KEV addition or public PoC, either of which should raise patch urgency.

Affected
Google Android (AOSP)
Estimated exposure
masspotentially millions to billions of devices (subset of Android's ~3 billion active devices), pending version disclosure — Google's Android CNA assignment plus the standard bulletin wording indicates a core Android platform flaw, and core AOSP components ship on the overwhelming majority of the ~3 billion active Android devices worldwide, so even a narrow…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness
CWE-362, CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.