Impact
_one_sswrp in Android’s init.c can allow a local attacker to gain system execution privileges. The flaw does not require any user interaction and can be triggered by arbitrary local exploitation attempts, potentially allowing the attacker to run code as the system user or to modify system settings. The vulnerability is a classic example of a local privilege escalation that could compromise the entire device if exploited, with the associated weakness being an Improper Initialization that results in unintended privilege elevation.
Affected Systems
The flaw exists in Google Android. No specific Android version is listed in the CNA data, so the vulnerability may affect any device running the affected kernel code that contains the buggy ac_init_one_sswrp implementation. Updated devices that have applied the current September 1, 2026 security patch are presumed to be fixed.
Risk and Exploitability
The CVSS score is 6.7, indicating a moderate severity. The EPSS score is < 1 %, suggesting a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The lack of a user‑interaction requirement and the ability to gain system privileges point to a high exploitable risk for local users. The likely attack vector is local, and any device operator or privileged user could trigger it without needing additional conditions beyond the presence of the vulnerable code.
OpenCVE Enrichment