Description
In openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is an out-of-bounds write in the openLogicalChannel function within Android’s smart card handling code. The missing bounds check can corrupt adjacent memory, allowing a local attacker to modify kernel or system memory. This extension of privileged access can lead to privilege escalation on the device, potentially enabling the attacker to execute further system commands without needing any additional execution rights. The flaw does not require user interaction, meaning a malicious application or a compromised component could exploit it autonomously.

Affected Systems

The affected product is Google Android. No specific version range is listed in the CNA data; therefore, devices running any Android revision prior to the fix that includes the updated openLogicalChannel implementation are potentially vulnerable. The vulnerability is present in multiple source files, indicating a widespread change across the Android platform.

Risk and Exploitability

The CVSS score of 7.8 reflects a moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that known exploitation activity is not reported at this time. The vulnerability is local, meaning executable code does not need to be injected, and no additional privileges are needed beyond the user who can invoke the vulnerable function. Exploitation is likely feasible in environments where a malicious application can access logical channel APIs or where device management delegates such capabilities to untrusted components.

Generated by OpenCVE AI on September 9, 2026 at 14:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Android operating system to the latest security patch that includes the fixed implementation of openLogicalChannel.
  • Restrict access to the logical channel APIs so that only trusted or enterprise‑approved applications can invoke them, utilizing device administration or application whitelisting policies.
  • Reboot the device after applying the patch and policy changes to ensure that the new memory bounds checks take effect and to clear any corrupted data.

Generated by OpenCVE AI on September 9, 2026 at 14:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Possible Out‑of‑Bounds Write in Android openLogicalChannel Leading to Local Privilege Escalation

Wed, 09 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-08T20:32:09.886Z

Reserved: 2026-06-16T17:41:51.647Z

Link: CVE-2026-55285

cve-icon Vulnrichment

Updated: 2026-09-08T20:31:57.895Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:01.727

Modified: 2026-09-25T13:11:48.003

Link: CVE-2026-55285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:00:03Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')