Executive brief
Android's runtime system contains a vulnerability where integer overflow in multiple functions can cause out-of-bounds memory writes. An attacker with local access to the device can exploit this flaw to escalate their privileges without requiring additional permissions or user interaction, potentially gaining full control of the affected device.
Technical details
The vulnerability is an integer overflow that results in out-of-bounds write operations in multiple functions within the Android Runtime component. The flaw allows local privilege escalation (EoP) with no additional execution privileges required and no user interaction needed for exploitation. The root cause is improper integer validation before memory operations, allowing an attacker to write to memory locations outside intended bounds. Patches have been released for Android 14, 15, 16, 16-qpr2, and 17 in the AOSP repository as of the September 2026 security patch level (2026-09-05 or later).
Affected products
- Google Android 14, 15, 16, 16-qpr2, 17
Timeline
- 2026-09-08: disclosed: Published in Android Security Bulletin
- 2026-09-05: patched: Security patch level 2026-09-05 or later addresses the issue