Description
In checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

In RoutingManager.cpp, a missing bounds check in checkUiccListenConfigNeeded can cause an out‑of‑bounds write to memory. This flaw falls under CWE‑120 and can be leveraged to achieve remote code execution with no additional privileges. Because the vulnerability does not require user interaction, a malicious actor could trigger it whenever the affected component is executed.

Affected Systems

The flaw affects the Android platform from Google. No specific Android OS version is listed in the advisory, so all releases that contain the unpatched RoutingManager.cpp are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 8.0 indicates a high severity, with exploitation capable of compromising the device. The EPSS score of < 1% suggests a very low likelihood of exploitation currently. Based on the description, it is inferred that the likely attack vector is local or network interaction with the RoutingManager component, as the flaw does not require user interaction or privilege escalation. Because the vulnerability is not listed in KEV, it may not be actively exploited yet, but the high severity warrants monitoring.

Generated by OpenCVE AI on September 9, 2026 at 20:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security patch that addresses the bounds check in RoutingManager.cpp
  • If the device cannot be updated immediately, disable or uninstall UICC‑dependent services or apps that invoke RoutingManager functionality
  • After applying the patch, reboot the device to ensure all processes use the updated code

Generated by OpenCVE AI on September 9, 2026 at 20:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-08T20:24:18.849Z

Reserved: 2026-06-16T17:41:51.646Z

Link: CVE-2026-55277

cve-icon Vulnrichment

Updated: 2026-09-08T20:23:59.649Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:01.600

Modified: 2026-09-25T13:11:22.817

Link: CVE-2026-55277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:00:03Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')