Description
In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The function do_sss_aes_gcm_256_op in crypto‑aes.c omits a bounds check, allowing an out‑of‑bounds read of memory beyond the intended bounds. An attacker who already holds system execution privileges can read that data, resulting in local information disclosure. The vulnerability does not require user interaction, so any local user with elevated permissions can exploit it. The flaw exists in the Android AES GCM implementation, specifically within the crypto‑aes.c source code used across Google Android devices.

Affected Systems

Google Android devices are affected, as identified in the Google security bulletin referenced in the advisory. Specific affected versions are not enumerated in the CVE entry; 2026‑09‑01 security bulletin remain at risk, while devices that have applied the patch are considered safe.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate severity. Because exploitation requires system execution privileges, the vulnerability is local and can only be abused by an adversary who has some level of elevated access to the device. The EPSS score of < 1 % indicates a very low likelihood of exploitation, and the overall risk remains low.

Generated by OpenCVE AI on September 20, 2026 at 14:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the 2026‑09‑01 security bulletin update.
  • Ensure your device is running the latest Android OS version to receive all security fixes.
  • Audit installed applications for unnecessary system‑level permissions and remove any that are not required.

Generated by OpenCVE AI on September 20, 2026 at 14:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Android AES GCM Cryptographic Function Enables Local Information Disclosure

Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Android AES GCM Function

Wed, 16 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Android AES GCM Function

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
CWE-125
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-15T20:33:58.839Z

Reserved: 2025-10-23T08:45:23.331Z

Link: CVE-2026-0177

cve-icon Vulnrichment

Updated: 2026-09-15T20:33:54.150Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:14.163

Modified: 2026-09-21T17:22:40.650

Link: CVE-2026-0177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-125

    Out-of-bounds Read