Description
In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-06-01
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from an out‑of‑bounds write caused by a heap buffer overflow in the LoadedArsc.cpp component of Android. The flaw allows a local attacker to overwrite neighbouring memory on the heap, potentially modifying program state or crafting data that alters control flow. The impact is a local escalation of privilege, meaning an attacker who already has a user‑level session can obtain higher permissions without executing arbitrary code or requiring additional privileges. The weakness involves a heap buffer overflow (CWE-122) that results in an out‑of‑bounds write.

Affected Systems

Google Android devices are affected, with the specific affected versions not disclosed in the advisory. The vulnerability resides in the core platform component for resource extraction, so all installations that include this code are potentially impacted.

Risk and Exploitability

The severity of the flaw is quantified by a CVSS score of 7.8. The EPSS score is not available, indicating that while exploitation potential exists, there is no publicly known or documented exploitation activity at this time. The flaw is local; it does not require network or user interaction, but any user with physical access or the ability to sideload applications that exercise the faulty loader can exploit it. Google has not listed it in the CISA KEV catalog, though the lack of such listing does not remove the risk. Potential attackers would most likely trigger the overflow by loading specially crafted ARSC files or by abusing an app that uses the resource extraction API in a vulnerable manner.

Generated by OpenCVE AI on June 2, 2026 at 02:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Android security update that includes the fix for the heap buffer overflow in the LoadedArsc component.
  • Limit the use of applications that can load or trigger the vulnerable ARSC parsing code; remove or update any untrusted or unsigned apps that may attempt such operations.
  • Monitor device logs for evidence of crashes or privilege escalation and report anomalous behavior to Google’s Android Security team.

Generated by OpenCVE AI on June 2, 2026 at 02:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow Leading to Local Privilege Escalation in Android Resource Loader

Tue, 02 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Heap Buffer Overflow in Android's LoadedArsc Component
Weaknesses CWE-787

Mon, 01 Jun 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Mon, 01 Jun 2026 23:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Heap Buffer Overflow in Android's LoadedArsc Component
Weaknesses CWE-787

Mon, 01 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-06-01T22:40:18.827Z

Reserved: 2025-10-15T15:43:03.878Z

Link: CVE-2026-0100

cve-icon Vulnrichment

Updated: 2026-06-01T22:35:25.404Z

cve-icon NVD

Status : Received

Published: 2026-06-01T22:16:23.730

Modified: 2026-06-01T23:16:18.083

Link: CVE-2026-0100

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T02:30:16Z

Weaknesses