CVE-2026-0171
massOut-of-Bounds Write Enabling Remote Code Execution in Google Android
CVE-2026-0171 is an out-of-bounds write (CWE-787) caused by a logic error in multiple code locations in Google Android, disclosed through Google's Android vulnerability management program. The flaw is exploitable over the network, requires only low attacker privileges, and needs no user interaction, so exploitation can occur without any victim action. Successful exploitation yields remote code execution, allowing an attacker to run code in the context of the vulnerable component without gaining additional privileges. The specific Android components and affected version ranges are not detailed in the available data, so any device without the corresponding security patch level should be treated as potentially affected. There is no known public proof of concept, the CVE is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Deploy the Android Security Bulletin update that addresses CVE-2026-0171 via OEM/carrier OTA channels and verify each managed device's security patch level. Because no user interaction is required, prioritize devices that run network-reachable apps or services and accelerate patching for high-value users. Track the Android Security Bulletin for the component and version specifics so you can scope your fleet accurately.
| Google Android | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.