← Back

CVE-2026-0095

nvd nist
Published: Jun 1, 2026Modified: Jul 22, 2026

JSON object

Loading...
8.0
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected (6)

Products: Google: Android
1 product
Android
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Google
Version 14.0
Version 15.0
Version 16.0
Version 16.0 qpr2_beta_1
Version 16.0 qpr2_beta_2
Version 16.0 qpr2_beta_3

References (1)

Timeline

No history available yet.