PT-2026-49796 · Google · Android

Published

2026-06-16

·

Updated

2026-06-16

·

CVE-2026-0137

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In edgetpu sync fence group shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2026-0137

Affected Products

Android