Description
In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch ASAP
AI Analysis

Impact

The gmc_mb_msg_handler function in gmc_mba.c contains a confused‑deputy memory corruption flaw that permits a local attacker to gain system execution privileges, resulting in unchecked escalation of privileges. This weakness is classified as CWE‑441 and enables a local user to execute arbitrary code with elevated rights.

Affected Systems

Android devices rolled out by Google, including Pixel smartphones affected in the September 2026 security bulletin. No specific Android version numbers are listed; the vulnerability exists in any build containing the affected gmc_mba component.

Risk and Exploitability

The CVSS score of 6.7 indicates moderate severity, and the EPSS score is < 1%, while the issue is not listed in CISA’s KEV catalog. Based on the description, user interaction is not required for exploitation. This implies that a local attacker with device access can exploit the flaw, elevating privileges to the system level. Based on the description, the vulnerability could allow an attacker to compromise device integrity. The lack of disclosed mitigation or workaround by Google suggests that the primary defense is to apply the vendor’s patch. Until a patch is available, devices remain vulnerable to local privilege escalation attacks.

Generated by OpenCVE AI on September 20, 2026 at 14:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Android security patch released by Google that addresses the memory corruption in gmc_mba.c.
  • If a patch is not yet available, disable or uninstall applications that may invoke the gmc_mb_msg_handler component to reduce the attack surface.
  • Limit device usage to trusted local users only and monitor for any unauthorized privilege escalation attempts.

Generated by OpenCVE AI on September 20, 2026 at 14:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via gmc_mb_msg_handler Memory Corruption in Android

Thu, 17 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Confused Deputy in Android gmc_mb_msg_handler

Wed, 16 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Confused Deputy in Android gmc_mb_msg_handler

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-441
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:57:58.681Z

Reserved: 2026-06-23T16:03:12.303Z

Link: CVE-2026-56879

cve-icon Vulnrichment

Updated: 2026-09-15T20:59:22.699Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:23.690

Modified: 2026-09-21T17:19:34.230

Link: CVE-2026-56879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')