Out of Bounds Write Vulnerability in Android IDrmManagerService
CVE-2026-0010
8.4HIGH
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-0010?
The vulnerability in Android's IDrmManagerService component stems from a missing bounds check in the onTransact function, which can lead to an out of bounds write condition. This flaw poses a risk of local privilege escalation without the need for additional execution privileges or user interaction. Attackers can exploit this vulnerability to gain higher access levels than intended, potentially compromising system integrity.
Affected Version(s)
Android 16
Android 15
Android 14
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.