Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-56960: Software may let attackers gain admin rights remotely
CVE-2026-56960 · published 28 days ago
Summary
Certain parts of the program could be tricked into using memory that’s no longer valid, allowing an attacker to take control of the system from afar without needing any special access or user interaction. This could let them act as an administrator on your network. Apply the vendor’s updates or patches as soon as they are available to close the gap.
What to do
- Update google :unknown: to version Pixel-family specific:2026-09-05.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | android | Android kernel | |
| Android | :unknown: |
>= Pixel-family specific:0, < Pixel-family specific:2026-09-05 Fix: upgrade to Pixel-family specific:2026-09-05
|
Original advisory text
In multiple locations, there is a possible use-after-free due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User in...
In multiple locations, there is a possible use-after-free due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References
- https://source.android.com/security/bulletin/2026-09-01 Vendor Advisory
- https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 Vendor Advisory
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-416Use After Free
Timeline
Published1 Sep 2026
Updated27 Sep 2026
First seen8 Sep 2026
Track software like this
Free during beta