Impact
The Android system has an out-of-bounds write vulnerability caused by improper input validation. This flaw can be triggered without any user interaction and may allow a local attacker to gain system execution privileges, enabling full control over the device. The weaknesses involve CWE‑20 and CWE‑787.
Affected Systems
The vulnerability affects the Android operating system from Google. No specific version numbers are supplied in the CVE data; the issue was reported in a September 2026 security bulletin, so devices running that release or earlier are potentially affected. The CVSS score of 6.7 and an EPSS score of less than 1% indicate a medium severity risk with a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog.
Risk and Exploitability
The CVSS score of 6.7 indicates a medium severity vulnerability. With an EPSS score of less than 1% and the vulnerability not listed in CISA KEV, the likelihood of widespread exploitation remains low. The flaw requires a local attacker to have some execution capability and does not require user interaction, which means it is exploitable by an attacker who can run code on the device, such as through malicious applications or an already compromised device. Once exploited, the local privilege escalation can elevate the attacker to system execution privileges, allowing full control over the Android device.
OpenCVE Enrichment