Impact
A race condition in trusty_dput trigger an out‑of‑bounds write. When an attacker with local access exploits the contention, memory corruption occurs, allowing the attacker to obtain System execution privileges. The vulnerability does not require any user interaction and can be leveraged to fully compromise the device.
Affected Systems
The flaw is present in the Android Trusty component across all builds distributed via the Google Android platform, as issued in the September 2026 security bulletin. No specific release numbers are enumerated builds after that bulletin are affected.
Risk and Exploitability
The CVSS v3 score of 7 denotes a medium‑to‑high severity for local privilege escalation. The EPSS score of less than 1 % suggests low exploitation likelihood, yet the absence of user interaction and the need for System privileges mean an attacker with local access could abuse the flaw. The vulnerability is not listed in the CISA KEV catalog, but its impact remains significant if the device is compromised.
OpenCVE Enrichment