Description
In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

_one_sswrp in Android’s init.c can allow a local attacker to gain system execution privileges. The flaw does not require any user interaction and can be triggered by arbitrary local exploitation attempts, potentially allowing the attacker to run code as the system user or to modify system settings. The vulnerability is a classic example of a local privilege escalation that could compromise the entire device if exploited, with the associated weakness being an Improper Initialization that results in unintended privilege elevation.

Affected Systems

The flaw exists in Google Android. No specific Android version is listed in the CNA data, so the vulnerability may affect any device running the affected kernel code that contains the buggy ac_init_one_sswrp implementation. Updated devices that have applied the current September 1, 2026 security patch are presumed to be fixed.

Risk and Exploitability

The CVSS score is 6.7, indicating a moderate severity. The EPSS score is < 1 %, suggesting a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The lack of a user‑interaction requirement and the ability to gain system privileges point to a high exploitable risk for local users. The likely attack vector is local, and any device operator or privileged user could trigger it without needing additional conditions beyond the presence of the vulnerable code.

Generated by OpenCVE AI on September 20, 2026 at 14:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Android security patch released by Google (e.g., the September 1, 2026 update) to remove the logic error in ac_init_one_sswrp.
  • If a patch is not yet available or cannot be applied, restrict local user accounts by disabling or limiting the functionality that triggers ac_init_one_sswrp, or enforce a least‑privilege policy for processes that call this function.
  • Monitor system logs for unusual privilege‑escalation attempts and consider enabling additional security controls such as SELinux or app sandboxing to contain potential exploitation events.

Generated by OpenCVE AI on September 20, 2026 at 14:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Android’s ac_init_one_sswrp Function

Thu, 17 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Android Local Privilege Escalation via Logic Error in ac_init_one_sswrp
Weaknesses CWE-665

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Android Local Privilege Escalation via Logic Error in ac_init_one_sswrp
Weaknesses CWE-665

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T16:40:27.159Z

Reserved: 2025-10-23T08:45:36.637Z

Link: CVE-2026-0186

cve-icon Vulnrichment

Updated: 2026-09-16T16:39:31.403Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:14.460

Modified: 2026-09-21T17:22:15.563

Link: CVE-2026-0186

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:15:08Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure