Impact
The gmc_mb_msg_handler function in gmc_mba.c contains a confused‑deputy memory corruption flaw that permits a local attacker to gain system execution privileges, resulting in unchecked escalation of privileges. This weakness is classified as CWE‑441 and enables a local user to execute arbitrary code with elevated rights.
Affected Systems
Android devices rolled out by Google, including Pixel smartphones affected in the September 2026 security bulletin. No specific Android version numbers are listed; the vulnerability exists in any build containing the affected gmc_mba component.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, and the EPSS score is < 1%, while the issue is not listed in CISA’s KEV catalog. Based on the description, user interaction is not required for exploitation. This implies that a local attacker with device access can exploit the flaw, elevating privileges to the system level. Based on the description, the vulnerability could allow an attacker to compromise device integrity. The lack of disclosed mitigation or workaround by Google suggests that the primary defense is to apply the vendor’s patch. Until a patch is available, devices remain vulnerable to local privilege escalation attacks.
OpenCVE Enrichment