Impact
An out‑of‑bounds write can occur in several parts of the Android kernel because a bounds check is omitted. This buffer overrun (CWE‑787) allows a local attacker to corrupt adjacent memory and gain system execution privileges without requiring any user interaction.
Affected Systems
The vulnerability targets the Android operating system supplied by Google. The CNA vendor list indicates the entire OS, and no particular releases are named. Users should verify whether their device is covered by the 2026‑09‑01 security bulletin and apply the corresponding patch if available.
Risk and Exploitability
The CVSS score of 6.7 represents a medium severity, while the EPSS score of less than 1% indicates a very low probability of exploitation. The flaw can be exploited locally; because no user interaction is needed, a malicious application or compromised routine on the device could raise its privileges to system level. The vulnerability is not listed in CISA’s KEV catalog, suggesting that no active exploitation has been observed.
OpenCVE Enrichment