Description
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch
AI Analysis

Impact

In the Android runtime source file rw_mfc.cc, the function rw_mfc_handle_read_op performs an incorrect bounds check, enabling a local attacker to write data past the end of a buffer. This could lead to a local privilege escalation without requiring additional execution privileges or user interaction. An exploit could corrupt memory, potentially allowing an attacker to elevate privileges to a local privileged user.

Affected Systems

The flaw affects Google’s Android contain the vulnerable MFC handling component. Versions are not explicitly disclosed, but any build that includes the uncorrected rw_m or unsupported ROMs that have not applied the official patch are likewise exposed.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity Local Privilege Escalation. The EPSS score of less than 1% suggests that, although the vulnerability is severe, the probability of exploitation in the wild is currently low. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is local; it does not require user interaction and no additional execution privileges beyond the process’s existing permissions are needed. The exposure remains significant in environments where untrusted applications run with elevated rights.

Generated by OpenCVE AI on September 11, 2026 at 02:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security patch or operating system build that includes the fix for the out‑of‑bounds write in rw_mfc_handle_read_op.
  • If the device runs a custom or unsupported ROM and cannot receive the official patch, replace the ROM with a Google‑approved build that contains the fix or patch the source code manually through the build system to correct the bounds check.
  • Maintain SELinux enforcement and restrict the permissions of user processes that can invoke MFC read operations, ensuring that only trusted applications have access to the vulnerable functionality.

Generated by OpenCVE AI on September 11, 2026 at 02:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Android MFC Handling Allows Local Privilege Escalation

Thu, 10 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Android's MFC Handler Allows Local Privilege Escalation

Thu, 10 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Android's MFC Handler Allows Local Privilege Escalation

Thu, 10 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Android Local Privilege Escalation via Out‑of‑Bounds Write in MFC Handle Read Operation
Weaknesses CWE-123
CWE-787

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Android Local Privilege Escalation via Out‑of‑Bounds Write in MFC Handle Read Operation
Weaknesses CWE-123
CWE-787

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T13:35:33.331Z

Reserved: 2026-06-02T14:29:35.576Z

Link: CVE-2026-49884

cve-icon Vulnrichment

Updated: 2026-09-10T13:35:30.393Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:58.660

Modified: 2026-09-23T19:20:37.657

Link: CVE-2026-49884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T02:15:10Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')