Impact
The vulnerability is a use‑after‑free caused by improper locking in multiple locations of the Android operating system. An attacker who already has local access can trigger the freed memory use without needing any additional execution rights, allowing them to elevate privileges on the device. The flaw can lead to full compromise of user data and system configuration due to the local privilege escalation it enables.
Affected Systems
Android devices manufactured by Google, including Pixel phones. No specific version numbers are listed in the advisory. The patching information is available in the September 1, 2026 security bulletin. All affected devices must be updated to the latest patched build.
Risk and Exploitability
The vulnerability has no public exploit data and is not listed in the CISA KEV catalog, but because it allows local privilege escalation without user interaction, the risk to users owning a device that can be accessed by an attacker is high. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, but the severity of potential compromise warrants prompt action.
OpenCVE Enrichment