ZeroHour

CVE-2026-49921

mass

Heap Buffer Overflow RCE in Android OS (September 2026 Security Update)

CVSS 3.1
9.8 critical
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-49921 is a memory-safety vulnerability in the Android operating system in which a heap buffer overflow (CWE-122) is present in multiple locations in the affected code. It is remotely exploitable over the network with no authentication, no additional privileges, and no user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N). A successful attack yields remote code execution with high impact on confidentiality, integrity, and availability, reflected in the critical CVSS 3.1 base score of 9.8. Affected parties are users of Android devices covered by the September 2026 Android Security Update, though the bulletin-level data does not specify the affected component or exact version ranges. As of now there is no known exploitation in the wild, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Apply the September 2026 Android Security Update as soon as your device OEM delivers it, and confirm the Android security patch level now reads September 2026 or later (check Settings > About phone). Because rollout is manufacturer-dependent, prioritize managed and internet-exposed Android fleets (e.g., via MDM) for early patching and track OEM advisories for your specific models. No public PoC or configuration-based workaround is documented; memory-safety flaws cannot be mitigated by settings, so patching is the primary defense.

Affected
Google Android OS (component(s) addressed in the September 2026 Android Security Bulletin)
Estimated exposure
masshundreds of millions of Android devices (order of magnitude; Android's global active base exceeds ~3 billion devices, scoped to devices eligible for the… — Android runs on roughly 3 billion active devices worldwide and monthly security bulletins of this type typically apply across the broad population of supported devices, although the specific affected component and version scope is not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google's September 2026 Android bulletin fixes over 30 critical flaws, including no-interaction system RCEs, a TIPC kernel RCE and a Qualcomm closed-source bug

Google's Android Security Bulletin for September 2026 (patch levels 2026-09-01 and 2026-09-05) fixes numerous critical System remote code execution flaws, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919 and CVE-2026-49921, none requiring user interaction or additional privileges. It also addresses critical kernel issues including a TIPC RCE (CVE-2026-52993) and elevation-of-privilege flaws in NFC and protected KVM, plus a critical Qualcomm closed-source component flaw (CVE-2026-25289). Affected versions span Android 14 through 17; the 2026-09-05 patch level extends coverage to Android TV and chipset components, with high-severity fixes for Arm Mali, PowerVR, MediaTek, Unisoc and Qualcomm components.