Junglewise Threat Intelligence

CVE-2026-0095: Google Android Bluetooth integer overflow in l2c_fcr_clone_buf

CVE-2026-0095 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Bluetooth component of Android devices could allow a malicious application to gain elevated system privileges. This component manages wireless connections with peripherals like headphones and keyboards. If exploited, an attacker could bypass security restrictions to access sensitive data or perform unauthorized actions without any user interaction.

Technical details

An integer overflow vulnerability exists in the 'l2c_fcr_clone_buf' function within 'l2c_fcr.cc' of the Android Bluetooth stack. This flaw allows an attacker to trigger controlled heap corruption within the privileged Bluetooth process. The vulnerability is reachable locally and does not require specific execution privileges or user interaction. Successful exploitation enables local escalation of privilege (EoP). The issue is addressed in the June 2026 Android Security Bulletin with a security patch level of 2026-06-05 or later.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Vulnerability published in Android Security Bulletin and NVD.
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.

References

Related threats