Description
In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-10-06
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Patch ASAP
AI Analysis

Impact

This vulnerability arises from a missing bounds check in the wacom_hid_set_device_mode function of the wacom_sys.c driver. The missing check allows an out‑of‑bounds write, which can overwrite privileged memory and enable an attacker to elevate their privileges on the device without needing any additional execution privileges or user interaction.

Affected Systems

Affected systems are Android devices that include the Wacom HID driver, such as Pixel phones and tablets manufactured by Google. No specific firmware or OS versions are listed in the advisory, so all current and future builds that ship with this driver are considered potentially vulnerable until an update is released.

Risk and Exploitability

The exploit does not require user action, implying that an attacker could trigger it remotely by sending crafted HID input to the device. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, but the potential for privileged escalation suggests a high severity. The absence of a patch or workaround means the risk is current and should be mitigated by waiting for an official firmware update or applying device hardening measures.

Generated by OpenCVE AI on October 6, 2026 at 19:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Android firmware update that includes the patched Wacom HID driver.
  • Restrict physical access to the device by enabling a strong lock screen and disabling any unused stylus or USB HID interfaces that interact with the driver.
  • If the device does not require stylus input, consider disabling or removing the Wacom HID driver from the system firmware to eliminate the attack surface.

Generated by OpenCVE AI on October 6, 2026 at 19:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Wacom HID Driver Enables Physical Privilege Escalation on Android

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
Description In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-10-06T18:54:46.537Z

Reserved: 2026-06-23T16:12:13.079Z

Link: CVE-2026-56936

cve-icon Vulnrichment

Updated: 2026-10-06T18:54:30.496Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:15.093

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-56936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T19:45:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer