GoogleCVE-2025-36940
Google Android: use after free
High8.8CVE-2025-36940 · Published Aug 24, 2026 · updated Aug 31, 2026
Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP)
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Android Product | <= F30.1.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-416
More Google advisories
All Google| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 25 | Google Chrome: information disclosure | Medium4.3 | 152.0.7977.65 |
| Aug 25 | Google Chrome: information disclosure | Medium4.3 | 152.0.7977.65 |
| Aug 25 | Google Chrome: race condition | Low3.1 | 152.0.7977.65 |
| Aug 25 | Google Chrome: information disclosure | Medium6.5 | 152.0.7977.65 |
| Aug 25 | Google Chrome: improper authorization | High7.1 | 152.0.7977.65 |
| Aug 24 | Google Nest: denial of service | Critical10.0 | No fix yet |