Heap Corruption in Bluetooth Process of Android Devices
CVE-2026-0095
8HIGH
What is CVE-2026-0095?
A vulnerability has been identified in the Bluetooth process of Android devices, where an integer overflow in the l2c_fcr_clone_buf function may lead to controlled heap corruption. This can result in local escalation of privileges without requiring additional execution permissions or user interaction. Given the nature of this flaw, it poses a considerable risk in terms of system security.
Affected Version(s)
Android 16-qpr2
Android 16
Android 15