Impact
A memory safety flaw caused by integer overflow can allow a local user to elevate privileges without requiring additional execution rights. The overflow occurs in several parts of the code, enabling a malicious local process to write beyond intended bounds and gain higher authority on the device.
Affected Systems
Google Android devices that include the affected code as listed in the 2026‑09‑01 security bulletin. No specific product versions are enumerated, so any Android installation referenced in that bulletin is potentially susceptible.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for this local privilege escalation flaw. The EPSS score is less than 1%, and the issue is not listed in CISA’s KEV catalog, indicating limited public exploitation data. Because it requires a local presence, the attack vector is inferred to be any local user or compromised application that can trigger the overflow.
OpenCVE Enrichment