Description
In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: n/a
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

A heap buffer overflow exists in the gf_ta_test_set_config function of gf_ta_test.c within the Android platform. The overflow arises from a logic error that fails to enforce bounds on memory writes, enabling an attacker to corrupt memory and gain higher privileges locally. The vulnerability can be exploited without remote access or user interaction, meaning the affected device itself is a sufficient target.

Affected Systems

The flaw is found in Google’s Android operating system, specifically within the gf_ta_test.c component that is part of the platform’s test framework. No specific Android release versions are provided in the advisory, but the issue is referenced in the 2026 September security bulletin for Pixel devices, implying it may affect recent Pixel firmware builds.

Risk and Exploitability

The CVSS score is not disclosed, and the EPSS score is not available, yet the risk remains significant because local privilege escalation can lead to a full compromise of the device. The vulnerability is not listed in the CISA KEV catalog, but its exploitation could occur without user interaction or additional privileges, making it a high‑impact condition if a patch is not applied.

Generated by OpenCVE AI on September 16, 2026 at 00:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to the latest Android security patch that addresses the gf_ta_test_set_config heap error
  • If an update is not yet available, disable or restrict access to the gf_ta_test_set_config functionality through device management policies
  • Apply SELinux policies or app‑level sandboxing to limit the privileges available to code paths that could trigger the buffer overflow

Generated by OpenCVE AI on September 16, 2026 at 00:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-15T18:34:31.051Z

Reserved: 2026-07-02T05:34:02.657Z

Link: CVE-2026-58679

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-15T19:17:31.600

Modified: 2026-09-15T19:17:31.600

Link: CVE-2026-58679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:15:14Z

Weaknesses

No weakness.