Description
In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

The flaw is a heap buffer overflow inside gf_ta_test_set_config of the Android Test Framework, discovered in Google’s Android platform. The logic error in the code allows memory corruption that can localize an attacker’s privileges without requiring additional execution privileges or remote code execution. The vulnerability is a CWE‑122 flaw.

Affected Systems

The weakness exists in Android operating systems, specifically within the gf_ta_test.c component of Google’s test framework. The advisory references the 2026 September security bulletin for Pixel devices, indicating that recent Pixel firmware builds are likely impacted, but no specific Android release versions are cited.

Risk and Exploitability

The CVSS score of 8.4 denotes high severity for this local privilege escalation flaw. The EPSS score is less than 1 %, suggesting a low, but not negligible, likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw without user interaction by triggering the logic error, resulting in elevated local privileges.

Generated by OpenCVE AI on September 20, 2026 at 13:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the Android security update released in September 2026 as detailed in the official Android security bulletin.
  • If the device cannot receive the update, disable the gf_ta_test component or uninstall any test framework applications that may invoke gf_ta_test_set_config.
  • Ensure the device is running the latest firmware and regularly check Google’s Android security advisories for further patches.

Generated by OpenCVE AI on September 20, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Heap Buffer Overflow in Android Test Framework

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Thu, 17 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Android Test Framework Enables Local Privilege Escalation

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Android Test Framework Enables Local Privilege Escalation
Weaknesses CWE-122

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-17T03:56:26.400Z

Reserved: 2026-07-02T05:34:02.657Z

Link: CVE-2026-58679

cve-icon Vulnrichment

Updated: 2026-09-16T13:06:51.147Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:31.600

Modified: 2026-09-18T17:28:32.143

Link: CVE-2026-58679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:30:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow