Description
In parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Apply Update
AI Analysis

Impact

In the Android framework, a bug in the parseParts function of PduParser.java can cause a heap buffer out‑of‑bounds read. This flaw allows a local attacker to read memory beyond the intended bounds, leading to a privilege escalation on the device. No additional execution privileges or user interaction are required, enabling the attacker to perform malicious actions with a higher privilege level.

Affected Systems

The vulnerability is linked to Android operating systems distributed by Google. No specific Android releases or build numbers are enumerated in the entry, so all devices that include the affected PduParser code are potentially impacted until the vendor releases a patched build.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, and the EPSS score is not available, but the lack of user interaction and the local nature of the impact make exploitation relatively straightforward for an attacker who already has physical or local access to the device. The vulnerability is not listed in the CISA KEV catalog, which suggests no confirmed public exploits yet. The likely attack vector is a local adversary who can trigger packet parsing within the system or a compromised application that can invoke PduParser. The combination of the vulnerable buffer manipulation (CWE‑122) and the local privilege escalation potential makes this a significant concern for devices running the affected Android code.

Generated by OpenCVE AI on September 9, 2026 at 14:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security update provided by Google that fixes the buffer read issue in PduParser
  • Verify the firmware integrity and ensure the device receives all subsequent security patches
  • If an update is not available, restrict the use of services that load PduParser by disabling related features (e.g., VoLTE) or applying system‑level access controls to limit privileged app interaction

Generated by OpenCVE AI on September 9, 2026 at 14:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-08T20:17:57.329Z

Reserved: 2026-06-02T14:45:32.236Z

Link: CVE-2026-49932

cve-icon Vulnrichment

Updated: 2026-09-08T20:17:49.047Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:59.377

Modified: 2026-09-24T15:44:44.763

Link: CVE-2026-49932

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:15:01Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow