Description
In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a missing bounds check in the function gmc_phy_lp3_exit_restore_registers, which is defined in phy_power.c. This omission can allow a local attacker to modify hardware registers and gain System execution privileges, with no user interaction required.

Affected Systems

Google Android devices that implement the affected gmc_phy_lp3_exit_restore_registers function are susceptible. No specific Android version or device containing the vulnerable code may be impacted until patched.

Risk and Exploitability

The EPSS score is < 1%, indicating a very low exploitation probability, and the CVSS score of 7.8 reflects significant local privilege escalation potential. The flaw is not listed in CISA’s KEV catalog. An attacker would likely proceed from a malicious local program that gains a foothold on the device, then manipulate the registers to achieve privileged execution. The absence of an external trigger or network component limits the attack to devices directly compromised by local code execution.

Generated by OpenCVE AI on September 20, 2026 at 14:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Android OS security patch that eliminates the missing bounds check (CWE‑120) in gmc_phy_lp3_exit_restore_registers.
  • If no patch is available, enforce strict controls to prevent installation of apps that can run privileged local code, thereby reducing the risk of exploiting the CWE‑120 bounds‑check issue.
  • Monitor the device for abnormal register write activity that could signal an attempt to leverage the CWE‑120 flaw, and alert administrators as needed.

Generated by OpenCVE AI on September 20, 2026 at 14:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Missing Bounds Check in Android gmc_phy_lp3_exit_restore_registers

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Thu, 17 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Missing Bounds Check in gmc_phy_lp3_exit_restore_registers Enables Local Privilege Escalation on Android
Weaknesses CWE-119
CWE-20

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Missing Bounds Check in gmc_phy_lp3_exit_restore_registers Enables Local Privilege Escalation on Android
Weaknesses CWE-119
CWE-20

Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-17T03:56:24.205Z

Reserved: 2026-07-02T05:37:09.598Z

Link: CVE-2026-58695

cve-icon Vulnrichment

Updated: 2026-09-16T13:02:05.467Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:31.900

Modified: 2026-09-18T17:26:52.063

Link: CVE-2026-58695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')