Description
In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-06-01
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an integer overflow in the l2c_fcr_clone_buf function within Android’s Bluetooth subsystem. This overflow can corrupt heap memory when the function is invoked, potentially allowing an attacker running on the device to elevate privileges within the privileged Bluetooth daemon. The flaw requires no user interaction and does not grant additional execution privileges beyond what the attacker already possesses. The primary impact is therefore an escalation of local privileges rather than remote code execution or denial of service.

Affected Systems

Google Android devices operating the Bluetooth stack are affected. No specific Android version or build was enumerated in the provided data, so any device that incorporates the affected Bluetooth implementation may be at risk.

Risk and Exploitability

The absence of an EPSS score and the lack of listing in the CISA KEV catalog indicate that the exploit is not currently known to be employed in the wild, but the flaw can be triggered locally by any process that can influence the Bluetooth daemon. The attack vector is inferred to be local, leveraging the privileged nature of the Bluetooth process, and would likely require the attacker to have some level of local system access. Theoretically, the vulnerability could lead to a complete compromise of the device if an attacker gains control of the Bluetooth service, allowing broad access to other privileged components. The severity, reflected in a CVSS score of 8, indicates a high risk due to the privilege escalation potential, even though public exploitation evidence is absent.

Generated by OpenCVE AI on June 2, 2026 at 00:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Android security patch that addresses the Bluetooth integer overflow
  • Disable Bluetooth services or turn off Bluetooth if the feature is not needed
  • Apply any vendor-supplied patch or update as soon as it becomes available

Generated by OpenCVE AI on June 2, 2026 at 00:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Heap Corruption in Android Bluetooth Process

Mon, 01 Jun 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 23:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Heap Corruption in Android Bluetooth Process
First Time appeared Google
Google android
Weaknesses CWE-190
Vendors & Products Google
Google android

Mon, 01 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Description In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-06-02T03:56:18.869Z

Reserved: 2025-10-15T15:42:56.290Z

Link: CVE-2026-0095

cve-icon Vulnrichment

Updated: 2026-06-01T22:56:12.885Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-06-01T22:16:23.027

Modified: 2026-06-02T13:04:00.123

Link: CVE-2026-0095

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T01:00:13Z

Weaknesses