Impact
In Android’s crypto‑aes.c, the function do_sss_aes_gcm_256_op omits a bounds check, causing an out‑of‑bounds read. An attacker with system execution privileges could read memory that should not be accessible, leading to local disclosure of sensitive data. No user interaction is required for exploitation.
Affected Systems
Google Android devices are affected, as identified by the Google security bulletin referenced in the advisory. Specific affected versions are not enumerated in the CVE entry. Devices that have not yet applied the 2026‑09‑01 security bulletin remain at risk, while those that have applied the patch are considered protected.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity. Exploitation requires the attacker to already possess system execution privileges; therefore it is a local vulnerability and can only be abused by an adversary who has some level of elevated access to the device. Because KEV is not listed and no EPSS score is available, the current exploitation likelihood cannot be quantified from the available data.
OpenCVE Enrichment