Impact
The flaw is a heap buffer overflow inside gf_ta_test_set_config of the Android Test Framework, discovered in Google’s Android platform. The logic error in the code allows memory corruption that can localize an attacker’s privileges without requiring additional execution privileges or remote code execution. The vulnerability is a CWE‑122 flaw.
Affected Systems
The weakness exists in Android operating systems, specifically within the gf_ta_test.c component of Google’s test framework. The advisory references the 2026 September security bulletin for Pixel devices, indicating that recent Pixel firmware builds are likely impacted, but no specific Android release versions are cited.
Risk and Exploitability
The CVSS score of 8.4 denotes high severity for this local privilege escalation flaw. The EPSS score is less than 1 %, suggesting a low, but not negligible, likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw without user interaction by triggering the logic error, resulting in elevated local privileges.
OpenCVE Enrichment