CVE-2026-0029

8.4

Google · Android

A memory corruption vulnerability in the pkvm component of the Android kernel allows for local escalation of privilege without requiring user interaction.

Executive summary

A critical local privilege escalation vulnerability in the Android pkvm component exposes devices to potential compromise by allowing unauthorized escalation of privileges.

Vulnerability

The vulnerability originates from a logic error in the __pkvm_init_vm function within pkvm.c, resulting in memory corruption that permits a local attacker to gain elevated system privileges.

Business impact

The ability for a local attacker to escalate privileges to the level of the kernel poses a severe threat to device security and data integrity. This flaw could be leveraged to bypass sandbox protections, access sensitive user data, or gain persistent control over the affected hardware, justifying its high CVSS score of 8.4.

Remediation

Immediate Action: Apply the March 2026 Android security updates provided by the device manufacturer as soon as they become available.

Proactive Monitoring: Monitor system logs for unusual kernel activity or unexpected process crashes that may indicate exploitation attempts.

Compensating Controls: Since this is a local privilege escalation, ensure that untrusted applications are not installed on devices and maintain strict control over physical device access.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Given the potential for complete system compromise, organizations should prioritize the deployment of the March 2026 security patches across their mobile device fleets. Administrators must ensure that devices are updated immediately upon vendor release to mitigate the risk of local exploitation.

More Google CVEs

Sources