Description
In VPU, there is a possible out-of-bounds write due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

An out‑of‑bounds write in the Video Processing Unit (VPU) caused by a confused‑deputy condition allows an attacker to gain higher privileges on the device without acquiring additional execution rights. The flaw resides in a memory corruption vulnerability (CWE‑787) that is triggered by a mis‑handled authority escalation (CWE‑441). This could enable a local user to execute code or modify system state beyond their normal rights, effectively compromising the integrity of the device.

Affected Systems

The vulnerability applies to Android devices that include the VPU component, as identified by the vendor Google:Android. No specific device model, Android version, or firmware release has been documented in the available data, so any device containing the VPU and lacking the informed security patch could be affected.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity flaw. The EPSS score of < 1% shows that the likelihood of exploitation is very low but not zero. The flaw can be exploited locally without requiring user interaction, which lowers the practical barrier for an attacker. The vulnerability is not listed in the CISA KEV catalog, but the combination of high severity and ability to elevate local privileges warrants prompt attention.

Generated by OpenCVE AI on September 20, 2026 at 14:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Android security patch from Google as documented in the 2026‑09‑01 security bulletin
  • Ensure that the device firmware and kernel have been upgraded to the patched versions; if the update cannot be applied, reinstall the operating system from a verified source
  • If a patch is not feasible, isolate the device from network traffic and limit local administrative access to reduce the potential impact of privilege escalation

Generated by OpenCVE AI on September 20, 2026 at 14:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title VPU Out-of-Bounds Write Enables Local Privilege Escalation on Android Devices

Thu, 17 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title VPU Out-of-Bounds Write Enables Local Privilege Escalation on Android Devices

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-441
CWE-787
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In VPU, there is a possible out-of-bounds write due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:57:55.741Z

Reserved: 2026-06-23T16:13:58.908Z

Link: CVE-2026-56945

cve-icon Vulnrichment

Updated: 2026-09-15T20:57:26.015Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:28.457

Modified: 2026-09-21T17:18:33.580

Link: CVE-2026-56945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:15:08Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')

  • CWE-787

    Out-of-bounds Write