Impact
The vulnerability resides in the WriteImageToDisk function within runtime_image.cc. A logic error allows a crafted write operation to replace an existing system image file without verification. This flaw enables a local user to tamper with critical system binaries, thereby escalating privileges to root-level access without requiring any additional execution rights or user interaction.
Affected Systems
Google Android devices running any version that includes the flawed WriteImageToDisk implementation. The advisory points to all affected Android releases notified in the September 2026 security bulletin, but no specific version list is provided. All instances of the runtime_image.cc code containing the identified flaw are vulnerable.
Risk and Exploitability
CVSS score of 7.8 denotes high severity. EPSS score is not available, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The attack would require local authenticated access; no remote attack path is described. Because no user interaction is needed, a malicious app or local attacker could trigger the tampering, making this a high risk for devices without updated patches.
OpenCVE Enrichment