Impact
A heap buffer overflow exists in the gf_ta_test_set_config function of gf_ta_test.c within the Android platform. The overflow arises from a logic error that fails to enforce bounds on memory writes, enabling an attacker to corrupt memory and gain higher privileges locally. The vulnerability can be exploited without remote access or user interaction, meaning the affected device itself is a sufficient target.
Affected Systems
The flaw is found in Google’s Android operating system, specifically within the gf_ta_test.c component that is part of the platform’s test framework. No specific Android release versions are provided in the advisory, but the issue is referenced in the 2026 September security bulletin for Pixel devices, implying it may affect recent Pixel firmware builds.
Risk and Exploitability
The CVSS score is not disclosed, and the EPSS score is not available, yet the risk remains significant because local privilege escalation can lead to a full compromise of the device. The vulnerability is not listed in the CISA KEV catalog, but its exploitation could occur without user interaction or additional privileges, making it a high‑impact condition if a patch is not applied.
OpenCVE Enrichment