Impact
The vulnerability is a use‑after‑free caused by improper locking in multiple locations of the Android operating system. An attacker who already has local access can trigger the freed memory use without needing them to elevate privileges on the device. This flaw can lead to full compromise of user data and system configuration due to the local privilege escalation it enables.
Affected Systems
Android devices manufactured by Google, including Pixel phones. No specific version numbers are listed in the advisory. It can be inferred that all affected devices should be updated to the latest patched build, as the patching information is described in the September 1, 2026 security bulletin.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability. It has no public exploit data and is not listed in the CISA KEV catalog. The lack of required user interaction and ability to elevate privileges locally presents a high risk to users. The EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation, yet the severity of potential compromise warrants prompt action.
OpenCVE Enrichment