Impact
The vulnerability is located in the phNxpNciHal_ext_process_nfc_init_rsp function of the Android NFC HAL. The missing bounds check allows an out‑of‑bounds write that can overwrite arbitrary memory addresses. This flaw enables a local attacker to elevate privileges without needing additional execution privileges, potentially compromising system integrity and confidentiality.
Affected Systems
The flaw affects Google Android devices that include the vulnerable NFC HAL code. Although the issue is referenced in the 2026‑09‑01 security bulletin, no specific device models or Android versions are listed, implying that all devices running the affected firmware are potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 places the vulnerability in the high severity range. Because no user interaction is required and the flaw is local, the attack vector is readily exploitable by anyone with local access or privileged user rights. The EPSS score is reported as less than 1%, indicating a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment