Executive brief
Android's MountRegistry component contains a buffer overflow vulnerability that allows an attacker with local access to read data outside of allocated memory boundaries. This could enable an attacker to escalate their privileges without needing additional permissions, potentially gaining full device control and access to sensitive user data.
Technical details
The vulnerability is an out-of-bounds read due to a buffer overflow in the forEachLine function of MountRegistry.cpp. The flaw allows a local attacker to read memory outside intended buffer boundaries, which can be exploited to escalate privileges on the affected device. No additional execution privileges are required and user interaction is not needed for exploitation. The issue affects multiple Android versions, with patches available in AOSP versions 14, 15, 16, 16-qpr2, and 17.
Affected products
- Google Android 14, 15, 16, 16-qpr2, 17
Timeline
- 2026-09-08: disclosed
- 2026-09-01: patched