Local Privilege Escalation Vulnerability in IOMMU Management of KVM by Android
CVE-2026-58846

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-58846?

A vulnerability in the IOMMU management of KVM within the Android Kernel could allow a local attacker to escalate privileges. The flaw arises from a use after free condition in the kvm_iommu_map_sg function, where a missing permission check could permit unauthorized access. Notably, exploitation does not require user interaction, making the vulnerability especially concerning for system integrity.

Affected Version(s)

Android Android kernel

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.