Executive brief
Android's system framework contains a use-after-free vulnerability affecting core OS components used by all applications and system services. An attacker with local access can exploit this memory safety flaw to escalate privileges without requiring additional permissions, potentially gaining full control over the device.
Technical details
This use-after-free vulnerability exists in multiple locations within Android's Framework component due to a logic error in memory management. The vulnerability allows local privilege escalation (EoP) with no additional execution privileges required and no user interaction needed. Attack vector is local; the attacker must have initial local access to the device. Exploitation could allow an attacker to execute arbitrary code with elevated privileges. Patches are available in Android versions 16-qpr2 and 17, released on 2026-09-05 or later per the Android Security Bulletin.
Affected products
- Google Android 16-qpr2, 17 (patched versions; vulnerable in earlier versions)
Timeline
- 2026-09-08: disclosed: Published in Android Security Bulletin—September 2026