Impact
The flaw is an improper input validation that allows an attacker to supply specially crafted data to the Android kernel or framework. This bypasses standard checks and permits local privilege escalation, enabling an attacker to gain higher privileges without additional execution rights. The core weakness is identified as CWE-20, which pertains to boundary checks or validation failures, and can undermine the confidentiality, integrity, and availability of the device.
Affected Systems
Android devices running Android versions that have not received the September 2026 security update are affected. The vulnerability spans multiple kernel and framework components noted in the Android security bulletin; no precise build numbers are provided, so any device prior to the latest patch may be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 reflects high severity, while the EPSS score of 0.00068 indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attack vector is local, with no requirement for user interaction; a malicious application or a compromised component could deliver the crafted data leading to exploitation on the device.
OpenCVE Enrichment