Description
In multiple locations, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free caused by improper locking in multiple locations of the Android operating system. An attacker who already has local access can trigger the freed memory use without needing them to elevate privileges on the device. This flaw can lead to full compromise of user data and system configuration due to the local privilege escalation it enables.

Affected Systems

Android devices manufactured by Google, including Pixel phones. No specific version numbers are listed in the advisory. It can be inferred that all affected devices should be updated to the latest patched build, as the patching information is described in the September 1, 2026 security bulletin.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity vulnerability. It has no public exploit data and is not listed in the CISA KEV catalog. The lack of required user interaction and ability to elevate privileges locally presents a high risk to users. The EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation, yet the severity of potential compromise warrants prompt action.

Generated by OpenCVE AI on September 20, 2026 at 13:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Android security patch released by Google so future patches are installed automatically.
  • Configure the device to automatically download and install pending security updates through Settings > System > Updates.
  • Restrict physical access to the device by using a strong PIN, password, or biometric lock.

Generated by OpenCVE AI on September 20, 2026 at 13:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Leading to Local Privilege Escalation on Android

Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Exploit Enables Local Privilege Escalation in Android

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-667
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Exploit Enables Local Privilege Escalation in Android
Weaknesses CWE-416

Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In multiple locations, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-17T03:56:43.077Z

Reserved: 2026-06-23T16:08:36.835Z

Link: CVE-2026-56914

cve-icon Vulnrichment

Updated: 2026-09-16T15:29:16.731Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:26.410

Modified: 2026-09-21T17:17:58.413

Link: CVE-2026-56914

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:00:26Z

Weaknesses