Description
In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation
Action: Apply Patch
AI Analysis

Impact

An out‑of‑bounds write can occur in several parts of the Android kernel because a bounds check is omitted. This buffer overrun (CWE‑787) allows a local attacker to corrupt adjacent memory and gain system execution privileges without requiring any user interaction.

Affected Systems

The vulnerability targets the Android operating system supplied by Google. The CNA vendor list indicates the entire OS, and no particular releases are named. Users should verify whether their device is covered by the 2026‑09‑01 security bulletin and apply the corresponding patch if available.

Risk and Exploitability

The CVSS score of 6.7 represents a medium severity, while the EPSS score of less than 1% indicates a very low probability of exploitation. The flaw can be exploited locally; because no user interaction is needed, a malicious application or compromised routine on the device could raise its privileges to system level. The vulnerability is not listed in CISA’s KEV catalog, suggesting that no active exploitation has been observed.

Generated by OpenCVE AI on September 20, 2026 at 14:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Android security patch released in the 2026‑09‑01 bulletin for the affected device.
  • If a patch is not yet available, isolate the device or restrict privileged services to limit the attack surface, such as disabling unnecessary kernel modules or functions tied to the vulnerable code.
  • Monitor device logs for unexpected privilege escalation or abnormal memory access patterns, and prevent installation of applications from untrusted sources.

Generated by OpenCVE AI on September 20, 2026 at 14:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Android Out‑of‑Bounds Write Causing Local Privilege Escalation

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Thu, 17 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Android Out-of-Bounds Write Leading to Local Privilege Escalation

Wed, 16 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Android Out-of-Bounds Write Leading to Local Privilege Escalation

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:58:00.150Z

Reserved: 2026-06-23T16:28:17.723Z

Link: CVE-2026-57035

cve-icon Vulnrichment

Updated: 2026-09-15T21:04:04.308Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:30.830

Modified: 2026-09-18T17:31:24.720

Link: CVE-2026-57035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses