ZeroHour

CVE-2026-55351

mass

Integer-Overflow Out-of-Bounds Write in Android VPU Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-55351 is an out-of-bounds write in the VPU (video processing unit) software component, caused by an integer overflow (CWE-190 / CWE-787), disclosed by Google's Android device security CNA. It is a local privilege escalation: a malicious app or process already running on the device with low privileges can trigger the flawed VPU code path without any user interaction and with no additional execution privileges required. Successful exploitation gives the attacker full local compromise of confidentiality, integrity, and availability (CVSS 3.1: 7.8, AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Affected parties are Android devices whose system-on-chip includes the vulnerable VPU component, as identified in the corresponding Google/Android security bulletin. There is no known public proof of concept, the flaw is not in the CISA KEV catalog, and no exploitation in the wild has been reported.

What to do: Apply the Android security update that fixes this CVE as soon as the corresponding bulletin ships, and confirm the device's security patch level in Settings (About phone > Android security update) afterwards. Because exploitation requires a low-privileged local process, restrict sideloading and unknown sources, keep Google Play Protect enabled, and avoid untrusted apps until patched. Defenders should watch the Android/Pixel security bulletins for the fixed patch level tied to CVE-2026-55351 and prioritize fleet-wide updates for devices with VPU hardware.

Affected
Google (Android) VPU (video processing unit) component
Estimated exposure
massPotentially tens to hundreds of millions of Android devices, depending on which SoC vendor's VPU implementation is affected — Google's Android device security team assigned the CVE and VPU hardware blocks are ubiquitous across mobile SoCs (Android runs on roughly 3 billion active devices), but the advisory does not name the chip vendor or affected patch levels,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness
CWE-190, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.