Description
In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution leading to Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

An integer overflow occurs in the tt_face_colr_blend_layer function of ttcolr.c, which may allow an attacker to execute arbitrary code. The flaw does not require any additional execution rights and does not need user interaction to be exploited.

Affected Systems

The vulnerability affects Google's Android operating system. Specific affected build numbers, release versions, or patches are not supplied in the advisory, so all Android installations that include the vulnerable ttcolr.c implementation are potentially impacted. No version ranges are documented publicly.

Risk and Exploitability

The CVSS score is 7.8, which indicates moderate to high severity. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating limited public exploitation data to date. Based on the description, the attack vector is local and does not require user interaction, meaning any user or application running with access to the vulnerable component could trigger the flaw. This lack of dependency on user action raises the likelihood of successful exploitation in a compromised environment.

Generated by OpenCVE AI on September 10, 2026 at 17:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Android to the latest security patch that includes the fix.
  • If immediate upgrade is not possible, disable or restrict custom font rendering in affected applications, thereby blocking the vulnerable tt_face_colr_blend_layer function.
  • Monitor devices for anomalous privilege escalation activity and enforce strict SELinux policies and application sandboxing to limit damage.

Generated by OpenCVE AI on September 10, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Thu, 10 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Android tt_face_colr_blend_layer Integer Overflow Enables Remote Code Execution

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Android tt_face_colr_blend_layer Integer Overflow Enables Remote Code Execution
Weaknesses CWE-190

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T13:32:42.492Z

Reserved: 2026-06-02T14:43:25.467Z

Link: CVE-2026-49919

cve-icon Vulnrichment

Updated: 2026-09-10T13:32:39.582Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:59.093

Modified: 2026-09-24T15:47:16.387

Link: CVE-2026-49919

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:45:16Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound