CVE-2026-0122

8.4

Google · Android

A memory corruption vulnerability in the Android kernel allows for potential remote code execution without requiring user interaction or elevated privileges.

Executive summary

A critical memory corruption flaw in the Google Android kernel poses a severe risk of remote code execution, requiring immediate attention.

Vulnerability

This vulnerability involves multiple instances of out of bounds write errors resulting from memory corruption. It allows an unauthenticated attacker to achieve remote code execution without user interaction.

Business impact

The ability for an attacker to execute arbitrary code with kernel-level access presents a catastrophic risk to device integrity and user data privacy. Given the CVSS score of 8.4, this vulnerability could lead to total system compromise, unauthorized data exfiltration, and the installation of persistent malware, potentially impacting the entire user base of affected devices.

Remediation

Immediate Action: Consult the official Google Android Security Bulletin for March 2026 and apply the recommended kernel security patches to all affected devices immediately.

Proactive Monitoring: Monitor system logs for signs of unexpected crashes, kernel panics, or anomalous process behavior that could indicate memory corruption attempts.

Compensating Controls: Ensure that all security features, such as hardware-backed keystores and verified boot, are enabled to maintain system integrity while waiting for firmware updates.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability, combined with the lack of required user interaction, necessitates a rapid response. IT administrators should prioritize the deployment of the March 2026 security updates across all managed Android devices to neutralize the risk of remote code execution.

More Google CVEs

Sources