Description
In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation via Heap Buffer Overflow
Action: Immediate Update
AI Analysis

Impact

The vulnerability is a heap buffer overflow in the ihevcd_get_tu_data_size function of ihevcd_utils.c. Exploitation results in an out‑of‑bounds write that can elevate a local user’s privileges without granting additional execution privileges. The description states that no user interaction is required for exploitation, indicating that the attack is local and can be performed by any user with access to the affected component.

Affected Systems

The flaw exists in Google’s Android operating system. No specific Android releases are enumerated in the provided data, so all Android devices that include the implicated ih-e–VCD component could be affected.

Risk and Exploitability

The CVSS score of 7.8 classifies the issue as High severity. EPSS data is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Because user interaction is not needed, a determined attacker with local access can exploit the buffer overflow to gain elevated privileges, potentially leading to full system compromise. The attack vector is inferred to be local, as no remote channel is described and the description explicitly notes that exploitation can occur without additional user action.

Generated by OpenCVE AI on September 9, 2026 at 14:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Android security patch that addresses the ih‑e‑VCD heap buffer overflow.
  • Revoke or disable any applications that require elevated privileges until the patch is applied.
  • Apply application‑level updates or replacements for software that uses the affected component, and enforce a policy of least privilege for device administrators.

Generated by OpenCVE AI on September 9, 2026 at 14:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Android Local Privilege Escalation via Heap Buffer Overflow in ihevcd_utils

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-08T20:33:38.875Z

Reserved: 2026-06-16T17:43:25.295Z

Link: CVE-2026-55294

cve-icon Vulnrichment

Updated: 2026-09-08T20:33:27.993Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:01.923

Modified: 2026-09-24T19:28:55.373

Link: CVE-2026-55294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:00:03Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow