CVE-2026-0152
Awaiting Analysis Awaiting Analysis - Queue
Memory Corruption in OSMMapPMRGeneric via VMA Expansion

Publication date: 2026-06-16

Last updated on: 2026-06-16

Assigner: Google Devices

Description
In OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a system call to system call to maliciously expand the VMA out of bounds due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-16
Last Modified
2026-06-16
Generated
2026-06-17
AI Q&A
2026-06-16
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the OSMMapPMRGeneric function of the pmr_os.c file. It involves a logic error that allows a system call to maliciously expand the Virtual Memory Area (VMA) out of its intended bounds.

Because of this logic error, an attacker can exploit the system call to manipulate memory boundaries improperly.

This flaw can be leveraged without any user interaction and does not require additional execution privileges.

Impact Analysis

The primary impact of this vulnerability is local escalation of privilege.

An attacker who already has local access to the system could exploit this vulnerability to gain higher privileges than originally granted.

This could allow the attacker to perform unauthorized actions on the system without needing additional execution privileges or user interaction.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0152. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart