Impact
The function do_sss_aes_gcm_256_op in crypto‑aes.c omits a bounds check, allowing an out‑of‑bounds read of memory beyond the intended bounds. An attacker who already holds system execution privileges can read that data, resulting in local information disclosure. The vulnerability does not require user interaction, so any local user with elevated permissions can exploit it. The flaw exists in the Android AES GCM implementation, specifically within the crypto‑aes.c source code used across Google Android devices.
Affected Systems
Google Android devices are affected, as identified in the Google security bulletin referenced in the advisory. Specific affected versions are not enumerated in the CVE entry; 2026‑09‑01 security bulletin remain at risk, while devices that have applied the patch are considered safe.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity. Because exploitation requires system execution privileges, the vulnerability is local and can only be abused by an adversary who has some level of elevated access to the device. The EPSS score of < 1 % indicates a very low likelihood of exploitation, and the overall risk remains low.
OpenCVE Enrichment