Description
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch
AI Analysis

Impact

A logic error in the Android media framework’s rw_mfc_handle_read_op routine causes an out‑of‑bounds write that can overwrite memory structures. This flaw does not require any additional execution privileges or a remote attack vector and can be triggered by any local user who initiates the read operation. The result is the elevation of the attacker’s privileges on the device.

Affected Systems

The vulnerability is present in any Android_handle_read_op implementation. No specific version numbers are listed, so all current Android releases prior to the issuance of the official patch are considered at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploits in the wild at this time. Because the attack can occur without user interaction, a local attacker has a realistic chance of exploitation, though the overall likelihood remains low.

Generated by OpenCVE AI on September 11, 2026 at 03:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Android 2026‑09‑01 security patch from Google’s security bulletin to all affected devices.
  • Restrict media framework read operations by applying SELinux policy adjustments for unprivileged applications until the patch is fully deployed.
  • Monitor Google’s subsequent security releases for additional patches that address this or related vulnerabilities.

Generated by OpenCVE AI on September 11, 2026 at 03:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Android Media Framework Enables Local Privilege Escalation

Thu, 10 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Android Media Framework Enables Local Privilege Escalation

Thu, 10 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Android rw_mfc Handle Read Out-of-Bounds Write Privilege Escalation
Weaknesses CWE-787

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Android rw_mfc Handle Read Out-of-Bounds Write Privilege Escalation
Weaknesses CWE-787

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T14:31:29.580Z

Reserved: 2026-03-02T19:11:13.944Z

Link: CVE-2026-28639

cve-icon Vulnrichment

Updated: 2026-09-10T14:31:20.374Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:55.360

Modified: 2026-09-15T14:08:18.987

Link: CVE-2026-28639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T03:15:03Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure