Description
In multiple locations, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free caused by improper locking in multiple locations of the Android operating system. An attacker who already has local access can trigger the freed memory use without needing any additional execution rights, allowing them to elevate privileges on the device. The flaw can lead to full compromise of user data and system configuration due to the local privilege escalation it enables.

Affected Systems

Android devices manufactured by Google, including Pixel phones. No specific version numbers are listed in the advisory. The patching information is available in the September 1, 2026 security bulletin. All affected devices must be updated to the latest patched build.

Risk and Exploitability

The vulnerability has no public exploit data and is not listed in the CISA KEV catalog, but because it allows local privilege escalation without user interaction, the risk to users owning a device that can be accessed by an attacker is high. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, but the severity of potential compromise warrants prompt action.

Generated by OpenCVE AI on September 16, 2026 at 00:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security patch released by Google for your device.
  • Enable automatic security updates so future patches are installed automatically.
  • Restrict physical access to the device and use a strong PIN or biometric lock to block unauthorized local access.

Generated by OpenCVE AI on September 16, 2026 at 00:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-667
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Exploit Enables Local Privilege Escalation in Android
Weaknesses CWE-416

Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In multiple locations, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-17T03:56:43.077Z

Reserved: 2026-06-23T16:08:36.835Z

Link: CVE-2026-56914

cve-icon Vulnrichment

Updated: 2026-09-16T15:29:16.731Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:26.410

Modified: 2026-09-17T04:17:49.260

Link: CVE-2026-56914

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T01:00:14Z

Weaknesses