Description
In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

An incorrect bounds check in several Android system components can cause an out‑of‑bounds write, which may allow a local attacker to elevate privileges to system execution level without the need for user interaction.

Affected Systems

The vulnerability affects the Android operating system on Google devices as specified in the 2026‑09‑01 security bulletin. No specific version numbers are listed, so any device running the affected Android build should be considered at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.7, indicating a moderate severity. The EPSS score is < 1%, implying a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. Because user interaction is not required, a local attacker who gains initial foothold can exploit the out‑of‑bounds write to acquire system privileges, potentially allowing the execution of arbitrary code or further privilege escalation.

Generated by OpenCVE AI on September 17, 2026 at 10:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Android security patch announced in the 2026‑09‑01 bulletin to address the out‑of‑bounds write (CWE‑787).
  • Reboot the device after the patch is installed to ensure kernel updates take effect.
  • If the patch is not yet available for your device, wait for a future update or apply the fix manually from a trusted source when released.

Generated by OpenCVE AI on September 17, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Causing Local Privilege Escalation in Android System Components

Wed, 16 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Causing Local Privilege Escalation in Android System Components

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:58:07.124Z

Reserved: 2026-06-23T16:20:45.087Z

Link: CVE-2026-56972

cve-icon Vulnrichment

Updated: 2026-09-15T21:09:28.018Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:29.147

Modified: 2026-09-16T19:24:44.153

Link: CVE-2026-56972

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T10:30:15Z

Weaknesses