Junglewise Threat Intelligence

CVE-2026-0010: Google Android out-of-bounds write in DRM Manager Service

CVE-2026-0010 · Severity: high · CVSS 8.4 · Published 2026-03-02

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android Digital Rights Management (DRM) service could allow a malicious application installed on a device to gain elevated system privileges. This component is responsible for managing protected content like streaming media. If exploited, an attacker could bypass security restrictions to access sensitive data or perform unauthorized actions without any user interaction.

Technical details

An out-of-bounds write vulnerability exists in the 'onTransact' method within 'IDrmManagerService.cpp' of the Android Framework. The flaw is caused by a missing bounds check when processing IPC transactions. A local attacker can exploit this to achieve escalation of privilege (EoP) to a higher execution context. The vulnerability affects Android versions 14, 15, and 16. It was addressed in the March 2026 Android Security Bulletin (patch level 2026-03-05). Note: While some external mailing lists use the same ID for a 'Barrier' software flaw, the official CVE-2026-0010 refers to this Android Framework vulnerability.

Affected products

  • Google Android 14, 15, 16

Timeline

  • 2026-03-02: disclosed
  • 2026-03-02: advisory: Android Security Bulletin published
  • 2026-03-05: patched: Security patch level 2026-03-05 or later addresses this issue

References

Related threats