ZeroHour

CVE-2026-49918

mass

Local Privilege Escalation in Android via Integer Overflow Out-of-Bounds Write

CVSS 3.1
7.8 high
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-49918 is an out-of-bounds write in multiple Android functions caused by an integer overflow, likely when computing buffer sizes or offsets during memory operations. A local attacker who can already execute code in an unprivileged app context can trigger the overflow to write past buffer boundaries and escalate privileges, with no additional execution privileges and no user interaction required. Any Android device on an affected build is exposed, although the available data does not identify the specific component or version range. The flaw was addressed in the September 2026 Android security update; there is no public proof-of-concept, it is not in CISA KEV, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.

What to do: Apply the September 2026 Android security update as soon as your device OEM (Pixel, Samsung, etc.) delivers it, and verify managed fleets report the September 2026 patch level. Because exploitation requires local code execution rather than remote attack, prioritizing patching on devices that run untrusted third-party apps is a reasonable interim risk-reduction step. Watch the AOSP/OEM advisories for the component-level detail needed to scope specific version ranges.

Affected
Google (Android) Android
Estimated exposure
massbillions of devices (Android's global active install base, ~3B+ devices) — Because the vulnerable component and version range are not disclosed, the entire Android fleet is plausibly in scope pending AOSP bulletins, and Android's active device base exceeds three billion, so even a component-level subset likely…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In multiple functions, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google's September 2026 Android bulletin fixes over 30 critical flaws, including no-interaction system RCEs, a TIPC kernel RCE and a Qualcomm closed-source bug

Google's Android Security Bulletin for September 2026 (patch levels 2026-09-01 and 2026-09-05) fixes numerous critical System remote code execution flaws, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919 and CVE-2026-49921, none requiring user interaction or additional privileges. It also addresses critical kernel issues including a TIPC RCE (CVE-2026-52993) and elevation-of-privilege flaws in NFC and protected KVM, plus a critical Qualcomm closed-source component flaw (CVE-2026-25289). Affected versions span Android 14 through 17; the 2026-09-05 patch level extends coverage to Android TV and chipset components, with high-severity fixes for Arm Mali, PowerVR, MediaTek, Unisoc and Qualcomm components.