Executive brief
A missing bounds check in Android's stpropnci component allows local attackers to exploit a memory safety vulnerability and escalate their privileges without requiring any special execution permissions. This could allow a malicious app to gain elevated system access and compromise device security.
Technical details
The vulnerability exists in stpropnci_process_std of stpropnci_std.cc due to a missing bounds check in memory operations, resulting in a memory safety issue. The vulnerability can be triggered locally without additional execution privileges, and user interaction is not required for exploitation. An attacker can leverage this vulnerability to achieve local privilege escalation and gain elevated access to the Android system. The vulnerability affects Android 14 and later; patches are available in AOSP versions 14, 15, 16, 16-qpr2, and 17 as of the 2026-09-05 security patch level.
Affected products
- Google Android 14, 15, 16, 16-qpr2, 17
Timeline
- 2026-09-08: disclosed: Published in Android Security Bulletin
- 2026-09-05: patched: Patches released in AOSP versions 14, 15, 16, 16-qpr2, and 17