Description
In multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation
Action: Apply patch
AI Analysis

Impact

The vulnerability in fpc_tee_hal.c is caused by a logic error that creates a use‑after‑free condition. A local attacker can free memory that is later accessed or corrupted by malicious code, enabling the attacker to gain elevated privileges without requiring any prior elevated permissions or user interaction. This flaw endangers confidentiality, integrity, and availability by permitting privilege escalation on the device.

Affected Systems

Android devices supplied by Google that incorporate the fpc_tee_hal module within their Trusted Execution Environment subsystem. Any build that includes fpc_tee_hal.c and has not yet received the official security patch is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.4 classifies this as a high‑severity vulnerability. The EPSS score is less than 1 %, indicating a low probability of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. The attack vector is purely local, requiring an attacker to run a malicious process on the device; no additional execution privileges or user interaction are needed for exploitation.

Generated by OpenCVE AI on September 20, 2026 at 13:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Android security patch from Google that resolves the fpc_tee_hal.c use‑after‑free flaw.
  • If a patch is unavailable, restrict or disable access to TEE services for non‑trusted applications until an update can be applied.
  • Observe system logs for anomalous memory accesses or privilege escalation events and deploy future patches immediately.

Generated by OpenCVE AI on September 20, 2026 at 13:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Android TEE Leading to Local Privilege Escalation

Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in fpc_tee_hal.c Enables Local Privilege Escalation
Weaknesses CWE-416

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in fpc_tee_hal.c Enables Local Privilege Escalation
Weaknesses CWE-416

Tue, 15 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-17T03:56:40.559Z

Reserved: 2026-06-23T16:13:58.908Z

Link: CVE-2026-56941

cve-icon Vulnrichment

Updated: 2026-09-16T15:22:49.410Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:28.260

Modified: 2026-09-21T17:18:24.213

Link: CVE-2026-56941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:00:26Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure