Description
In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A heap buffer overflow in the function a2dp_vendor_opus_decoder_decode_packet within the a2dp_vendor_opus_decoder.cc source code allows an out‑of‑bounds write on the heap. This flaw can lead to local privilege escalation without requiring additional execution privileges or user interaction.

Affected Systems

The vulnerability exists in Google Android devices that include the a2dp_vendor_op no specific Android version or build identifiers, so the flaw applies to all affected releases until a vendor patch is released.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity for a local privilege escalation vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation at present, and the flaw is not listed in the CISA KEV catalog. Since the vulnerability does not require user interaction or elevated privileges, an attacker who already has local device access could exploit it. The likely attack vector is that the overflow could be triggered via an A2DP audio stream that uses the affected Opus codec; based on the description, this inference is grounded in the provided information.

Generated by OpenCVE AI on September 10, 2026 at 18:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security patch that contains the fix for the a2dp vendor Opus decoder overflow
  • Until the patch is applied, disable or restrict the Bluetooth A2DP profile to prevent unintended audio streams
  • Configure the device to keep Bluetooth disabled when not in use, enforce trusted device pairing only, and maintain a strong device lock and encryption to reduce local exploitation opportunities

Generated by OpenCVE AI on September 10, 2026 at 18:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Thu, 10 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Android A2DP Opus Decoder Leading to Local Privilege Escalation

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Android A2DP Opus Decoder Leading to Local Privilege Escalation
Weaknesses CWE-122

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T14:10:40.323Z

Reserved: 2026-05-12T17:34:26.824Z

Link: CVE-2026-45515

cve-icon Vulnrichment

Updated: 2026-09-10T14:10:37.775Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:57.437

Modified: 2026-09-24T15:26:22.773

Link: CVE-2026-45515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T19:00:11Z

Weaknesses