Impact
The flaw is caused by type confusion that lets the system read memory beyond intended bounds. An application that already has ordinary user‑level code execution can exploit the out‑of‑bounds read, which elevates its privileges to system level without requiring additional privileges or user interaction. The weakness is captured by CWE‑441 (Incorrect Argument Type) and CWE‑682 (Invalid Inheritance Handling).
Affected Systems
Android devices running the affected build, specifically Pixel phones advertised in the 2026‑09‑01 security bulletin. The CNA lists the entire Android platform as impacted, so any device on that Android release cycle is potentially vulnerable until the vendor releases a patch.
Risk and Exploitability
With a CVSS score of 8.4 to confidentiality, EPSS score of < 1% indicates a very low but non‑zero probability that an exploit will be seen in the wild, though the lack of a user‑interaction requirement means a malicious application can abuse the bug locally. The vulnerability is not yet in the CISA KEV catalog, so widespread exploitation has not been documented.
OpenCVE Enrichment