Description
In multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation
Action: Apply patch
AI Analysis

Impact

The Android system has an out-of-bounds write vulnerability caused by improper input validation. This flaw can be triggered without any user interaction and may allow a local attacker to gain system execution privileges, enabling full control over the device. The weaknesses involve CWE‑20 and CWE‑787.

Affected Systems

The vulnerability affects the Android operating system from Google. No specific version numbers are supplied in the CVE data; the issue was reported in a September 2026 security bulletin, so devices running that release or earlier are potentially affected. The CVSS score of 6.7 and an EPSS score of less than 1% indicate a medium severity risk with a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog.

Risk and Exploitability

The CVSS score of 6.7 indicates a medium severity vulnerability. With an EPSS score of less than 1% and the vulnerability not listed in CISA KEV, the likelihood of widespread exploitation remains low. The flaw requires a local attacker to have some execution capability and does not require user interaction, which means it is exploitable by an attacker who can run code on the device, such as through malicious applications or an already compromised device. Once exploited, the local privilege escalation can elevate the attacker to system execution privileges, allowing full control over the Android device.

Generated by OpenCVE AI on September 20, 2026 at 14:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Android security patch provided by Google in the September 2026 bulletin.
  • Restart the device after the patch installation to ensure all components load the updated code.
  • If the device is unable to receive the patch, restrict its use for sensitive operations until a later update is available.

Generated by OpenCVE AI on September 20, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Thu, 17 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Android Out-of-Bounds Write Leading to Local Privilege Escalation

Wed, 16 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Android Out-of-Bounds Write Leading to Local Privilege Escalation

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-787
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:58:11.840Z

Reserved: 2026-06-16T17:51:15.420Z

Link: CVE-2026-55332

cve-icon Vulnrichment

Updated: 2026-09-15T21:14:15.363Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:21.507

Modified: 2026-09-21T17:20:12.560

Link: CVE-2026-55332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:15:08Z

Weaknesses