Description
In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-03-10
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch ASAP
AI Analysis

Impact

The flaw resides in gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c and manifests a confused‑deputy permission logic error (CWE‑441). An attacker who can execute code on the device can cause the function to grant higher privileges than intended without needing additional execution rights. This allows a local user or malicious application to obtain system‑level access, compromising confidentiality, integrity, and availability of the device. The vendor notes that user interaction is not required for exploitation, indicating a purely local privilege escalation vector.

Affected Systems

Google Android devices and Android operating systems are affected. No specific version range is listed; the vulnerability applies across any build that includes the unpatched gmc_mba_ddr.c code. All users running Android should be aware, regardless of device model.

Risk and Exploitability

The CVSS score of 8.4 classifies this as High severity. The EPSS score is reported as less than 1%, indicating a low probability of widespread exploitation at this time, and it is not included in CISA’s KEV catalog. The attack requires local access; no network or elevated privileges are needed to trigger the bug. An exploit path would involve a local malicious process invoking the vulnerable function, leading to privilege escalation. The combined risk is moderate to high for users with unpatched devices, especially where the device is used to run untrusted applications.

Generated by OpenCVE AI on April 16, 2026 at 03:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Android device to the latest security patch level released by Google (see the March 1, 2026 bulletin)
  • If the device cannot be updated, restrict or remove access to the gmc module by disabling related services and tightening file permissions
  • Enable and monitor SELinux enforcement to block unauthorized privilege escalation attempts

Generated by OpenCVE AI on April 16, 2026 at 03:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 03:45:00 +0000

Type Values Removed Values Added
Title Local privilege escalation in Android gmc_ddr module due to confused deputy

Wed, 11 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Wed, 11 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-441
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 10 Mar 2026 22:30:00 +0000

Type Values Removed Values Added
References

Tue, 10 Mar 2026 21:30:00 +0000

Type Values Removed Values Added
References

Tue, 10 Mar 2026 21:00:00 +0000

Type Values Removed Values Added
Description In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-03-12T03:55:29.800Z

Reserved: 2025-10-23T08:42:58.319Z

Link: CVE-2026-0107

cve-icon Vulnrichment

Updated: 2026-03-11T15:01:21.754Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-10T21:16:44.117

Modified: 2026-03-11T17:14:30.117

Link: CVE-2026-0107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T03:30:06Z

Weaknesses