ZeroHour

CVE-2026-0171

mass

Out-of-Bounds Write Enabling Remote Code Execution in Google Android

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-0171 is an out-of-bounds write (CWE-787) caused by a logic error in multiple code locations in Google Android, disclosed through Google's Android vulnerability management program. The flaw is exploitable over the network, requires only low attacker privileges, and needs no user interaction, so exploitation can occur without any victim action. Successful exploitation yields remote code execution, allowing an attacker to run code in the context of the vulnerable component without gaining additional privileges. The specific Android components and affected version ranges are not detailed in the available data, so any device without the corresponding security patch level should be treated as potentially affected. There is no known public proof of concept, the CVE is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Deploy the Android Security Bulletin update that addresses CVE-2026-0171 via OEM/carrier OTA channels and verify each managed device's security patch level. Because no user interaction is required, prioritize devices that run network-reachable apps or services and accelerate patching for high-value users. Track the Android Security Bulletin for the component and version specifics so you can scope your fleet accurately.

Affected
Google Android
Estimated exposure
massPotentially millions to billions of Android devices (order-of-magnitude estimate; exact scope unknown until component/version details are published) — Google has publicly cited roughly 3 billion active Android devices, so even a narrowly scoped OS component flaw plausibly reaches millions of units pending patching.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.