Impact
An incorrect bounds check in several Android system components can cause an out‑of‑bounds write, which may allow a local attacker to elevate privileges to system execution level without the need for user interaction.
Affected Systems
The vulnerability affects the Android operating system on Google devices as specified in the 2026‑09‑01 security bulletin. No specific version numbers are listed, so any device running the affected Android build should be considered at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.7, indicating a moderate severity. The EPSS score is < 1%, implying a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. Because user interaction is not required, a local attacker who gains initial foothold can exploit the out‑of‑bounds write to acquire system privileges, potentially allowing the execution of arbitrary code or further privilege escalation.
OpenCVE Enrichment