Heap Buffer Overflow in Android Products by Google
CVE-2025-36906

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-36906?

A heap buffer overflow vulnerability exists in the ConvertReductionOp function within darwinn_mlir_converter_aidl.cc of Google Android. This flaw can allow an attacker to cause an out-of-bounds write, potentially leading to unauthorized local escalation of privileges. Exploitation does not require user interaction, making it critical for users to apply security updates to mitigate potential risks.

Affected Version(s)

Android Android kernel

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36906 : Heap Buffer Overflow in Android Products by Google