ZeroHour

CVE-2026-55285

mass

Out-of-Bounds Write in Android openLogicalChannel Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p0
Published
()
Modified
AI analysis

CVE-2026-55285 is an out-of-bounds write (CWE-120) in the openLogicalChannel routine of multiple files in the Android OS, caused by a missing bounds check. A local attacker needs no additional execution privileges and no user interaction to trigger the flaw, which corrupts memory and enables local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, AV:L/PR:L/UI:N). Any Android device carrying the affected platform code is exposed, though Google has not published affected version ranges in the available data; fixes ship in the September 2026 Android Security Bulletin. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and EPSS assigns a 0.1% probability of exploitation in the next 30 days, so no confirmed in-the-wild exploitation is known. The related September 2026 bulletin headline covers broader Android fixes including RCE bugs, but this specific flaw is a local privilege escalation, not a remote one.

What to do: Apply the September 2026 Android Security Bulletin as delivered by Google and OEMs (e.g., Samsung and other vendor monthly patch releases), and verify each device's Android security patch level is September 2026 or later via Settings > About phone > Android security update. Until patched, restrict untrusted local apps and device access, since exploitation requires only local code execution with no user interaction or special privileges. Monitor the Android security bulletin for published affected-version ranges, which are not yet enumerated in the available data.

Affected
Google Android OS (openLogicalChannel routine, multiple files)
Estimated exposure
mass~3 billion+ Android devices potentially affected (exact vulnerable-version scope unpublished) — Android runs on roughly 3 billion or more active devices globally and this is a platform-level flaw fixed in the monthly Android bulletin, so the realistic order of magnitude approaches the full Android install base; no published version…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness
CWE-120
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google's September 2026 Android bulletin fixes over 30 critical flaws, including no-interaction system RCEs, a TIPC kernel RCE and a Qualcomm closed-source bug

Google's Android Security Bulletin for September 2026 (patch levels 2026-09-01 and 2026-09-05) fixes numerous critical System remote code execution flaws, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919 and CVE-2026-49921, none requiring user interaction or additional privileges. It also addresses critical kernel issues including a TIPC RCE (CVE-2026-52993) and elevation-of-privilege flaws in NFC and protected KVM, plus a critical Qualcomm closed-source component flaw (CVE-2026-25289). Affected versions span Android 14 through 17; the 2026-09-05 patch level extends coverage to Android TV and chipset components, with high-severity fixes for Arm Mali, PowerVR, MediaTek, Unisoc and Qualcomm components.