CVE-2026-55301

Google · Android

A missing bounds check in the Wave6VpuDecFlush function of the Android kernel may result in an out-of-bounds write, potentially enabling local privilege escalation without user interaction.

Executive summary

A critical out-of-bounds write vulnerability in the Android kernel allows local attackers to escalate privileges without requiring user interaction.

Vulnerability

The vulnerability is an out-of-bounds write flaw located in the Wave6VpuDecFlush function within wave6.c. The issue allows an attacker with local access to achieve privilege escalation without needing specific execution privileges or user interaction.

Business impact

This vulnerability poses a significant risk to the integrity and security of the Android operating system. A successful exploit could grant an attacker elevated permissions, enabling them to bypass security controls, access sensitive user data, or gain full control over the device. Given the CVSS score of 8.4, this flaw is categorized as high severity and requires immediate attention to prevent unauthorized system access.

Remediation

Immediate Action: Consult the official Google Android security bulletin for the latest security patches and apply all available system updates to the affected devices immediately.

Proactive Monitoring: Monitor system logs for unusual kernel-level activity or unexpected process behavior that may indicate an attempt to exploit memory corruption vulnerabilities.

Compensating Controls: Ensure that all applications are installed from trusted sources and maintain strict device management policies to limit the potential for local unauthorized code execution.

Exploitation status

Public Exploit Available: exploit_available (unknown)

Analyst recommendation

Due to the potential for full privilege escalation, this vulnerability must be treated with high priority. Administrators should track the official Android security bulletins closely and deploy the relevant firmware or kernel updates as soon as they are made available by the vendor to neutralize this risk.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.4 (3.1)
  4. Analyst report written

Sources