CVE-2026-0037

8.4

Google · Android Kernel

A memory corruption vulnerability exists in ffa.c within the Android kernel due to a logic error, potentially allowing for local privilege escalation.

Executive summary

A critical memory corruption flaw in the Android kernel could allow a local attacker to gain elevated privileges on the affected device.

Vulnerability

The vulnerability is a memory corruption issue caused by a logic error in ffa.c, which permits an attacker to perform local elevation of privilege without requiring additional execution permissions or user interaction.

Business impact

Successful exploitation of this vulnerability allows an attacker to bypass standard security restrictions, resulting in a full compromise of system integrity and confidentiality. Given the CVSS score of 8.4, this vulnerability represents a significant risk as it grants attackers elevated access, which could be leveraged to install persistent malware or exfiltrate sensitive user data.

Remediation

Immediate Action: Apply the March 2026 Android Security Bulletin updates provided by Google or your device manufacturer as soon as they become available for your specific hardware.

Proactive Monitoring: Review system logs for unusual crashes or unexpected behavior in kernel-level processes that may indicate attempts to trigger memory corruption.

Compensating Controls: Ensure that Google Play Protect is enabled and that all device security settings are configured to restrict sideloading of untrusted applications, which limits the initial access vector required for exploitation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a high risk to Android device security due to the potential for privilege escalation. Security teams and device administrators should prioritize the deployment of the March 2026 security patches across their mobile device fleets to mitigate this risk.

More Google CVEs

Sources