Description
In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Update Android OS
AI Analysis

Impact

A memory safety flaw exists in the stpropnci_process_std function of stpropnci_std.cc due to a missing bounds check. The vulnerability can be exploited to gain local privilege escalation on an affected device without the need for any additional execution privileges. The description states that no user interaction is required for exploitation.

Affected Systems

The affected vendor is Google and the product is Android. The flaw resides in the stpropnci_process_std component, and there is no explicit version information provided in the CVE data.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, and the lack of an EPSS score means the current exploit probability is unknown. The vulnerability is listed as not part of the CISA KEV catalog. Because user interaction is not required and the flaw allows local privilege escalation, a local attacker—such as a user with access to the device—could exploit the issue. The known lack of more advanced privileges means the impact is limited to local privilege elevation rather than remote code execution.

Generated by OpenCVE AI on September 9, 2026 at 14:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security update that addresses the bounds‑check error in stpropnci_std.cc
  • If the vulnerable feature is not required, disable or restrict its use by removing the associated permissions from affected applications
  • Monitor system logs for signs of unauthorized privilege escalation attempts and consider enabling additional OS‑level vulnerability mitigation tools such as SELinux policies

Generated by OpenCVE AI on September 9, 2026 at 14:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Missing Bounds Check in stpropnci_process_std Enables Local Privilege Escalation

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-08T20:49:58.290Z

Reserved: 2026-07-02T05:56:29.150Z

Link: CVE-2026-58823

cve-icon Vulnrichment

Updated: 2026-09-08T20:49:48.927Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:02.873

Modified: 2026-09-24T16:33:33.693

Link: CVE-2026-58823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:00:03Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')