Impact
Android contains a missing bounds check that can lead to an out‑of‑bounds write. This flaw allows a local attacker to gain system execution privileges, compromising device integrity and confidentiality. The weakness is a classic memory corruption error (CWE‑787).
Affected Systems
The vulnerability impacts devices running Android, specifically those distributed by Google (Pixel devices). No specific OS release or build number is listed in the advisory, but the September 2026 security bulletin applies broadly to Android devices issued by Google at that time.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate severity for local attackers. The EPSS score of less than 1% suggests that exploitation is rare. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access and does not need user interaction, so any attacker who can run code on the device can potentially elevate to system level.
OpenCVE Enrichment