Impact
The gmc_mb_msg_handler function in gmc_mba.c contains a confused‑deputy memory corruption flaw that permits a local attacker to gain system execution privileges, resulting in unchecked escalation of privileges. This weakness is classified as CWE‑441 and enables a local user to execute arbitrary code with elevated rights.
Affected Systems
Android devices rolled out by Google, including Pixel smartphones affected in the September 2026 security bulletin. No specific Android version numbers are listed; the vulnerability exists in any build containing the affected gmc_mba component.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, and the EPSS score is < 1%, while the issue is not listed in CISA’s KEV catalog. Because user interaction is not required, a local attacker with physical or remote access to the device can exploit the flaw, elevating privileges to the system level. The lack of disclosed mitigation or workaround by Google suggests that the primary defense is to apply the vendor’s patch. Until a patch is available, devices remain vulnerable to local privilege escalation attacks that could compromise device integrity, confidentiality, and availability.
OpenCVE Enrichment