PT-2026-49792 · Google · Android

Published

2026-06-16

·

Updated

2026-06-16

·

CVE-2026-0133

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In smmu attach dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-0133

Affected Products

Android